Security at OMS.
This page is maintained by the OMS AI Nexus™ team to answer common security questions about the platform. It describes controls that are currently enabled — it is not an independent certification.
All traffic runs over TLS to the managed backend and edge runtime.
Every user-scoped table enforces RLS with policies scoped to authenticated identity.
Administrative actions require a verified admin role, checked server-side per request.
Uploaded assets live in a private storage bucket, served through short-lived signed URLs.
Platform & hosting
OMS AI Nexus™ runs on OMS AI Nexus managed cloud and an edge runtime for the application layer. Server secrets (service role, API keys) never leave the server runtime and are not exposed to the browser.
Responsible disclosure
If you believe you have found a security issue, please emailomsit.official@gmail.comwith steps to reproduce. Please do not publish details until we have had a reasonable opportunity to remediate. We do not pursue legal action against researchers who follow good-faith disclosure practices.
Contact
General security questions: omsit.official@gmail.com.
This document reflects current app-visible controls maintained by OMS AI Nexus™. It does not constitute a certification, warranty, or a substitute for a formal audit.