Orchestrated Multi-Model AI System

Security

OMMAIS is a small, independent site run by one person. This page says plainly how it protects you, and what it does not claim. Every statement here was checked against the site's own code.

Certifications: none

ommais.com is not SOC 2 audited and holds no ISO 27001 or similar certification. Those are reports written by independent auditors, and this site has never been through one. It has not had a formal penetration test either. If your organisation requires any of these from a vendor, OMMAIS does not meet that requirement today.

The site runs on Cloudflare, which holds its own SOC 2 and ISO 27001 certifications for its infrastructure (see Cloudflare's compliance page). That covers Cloudflare's systems, not this site's code.

Your conversations never pass through this site

OMMAIS Chat runs in your browser. Your questions go straight from your browser to the model service you are using — by default LLM7.io's free service; your own models through Ollama, where nothing leaves your computer; or a provider you added your own key for. This site has no server that runs a model or receives a conversation, so there is nothing here to leak. Which service your prompts go to is shown in the chat's status bar.

Cloud model services have their own privacy terms, and LLM7.io's free service is not audited as far as we know. Do not paste passwords, card numbers, health records or other sensitive information into any cloud AI model — here or anywhere else.

Saved conversations are encrypted on your device

Accounts

What the site keeps

The privacy page has the full detail.

Who else is involved

Reporting a security problem

If you find a vulnerability, please email eric.varney@yahoo.com with "Security" in the subject, and give a reasonable chance to fix it before making it public. There is no paid bug bounty, but reports are read, answered and credited if you would like. The same contact is published at /.well-known/security.txt.

Last reviewed 30 September 2026.