Security

Our commitment to protecting your data and the platform — Omniagentics Limited

SECURITY OVERVIEW

Omniagentics Limited — Platform Security Posture

At Omniagentics, security is not an afterthought — it is a foundational principle embedded in everything we build and operate. This document outlines our approach to protecting the Nexus Hub — our curated marketplace for professional software solutions — the data of our users and partners, and the integrity of our commission gateway and vendor-vetting infrastructure.

We apply industry best practices across all layers of our platform: application, infrastructure, data, and people. As a platform that handles sensitive business data, routes outbound referrals through a commission gateway, and vets vendors before they reach buyers, we hold ourselves to a high standard of operational security.

Security Pillars

Access Control

All access to platform systems and data is governed by role-based access control (RBAC). Administrative functions are restricted to authorised personnel only. Multi-factor authentication (MFA) is required for all privileged accounts.

Infrastructure Security

The Nexus Hub marketplace and its underlying platform are hosted on enterprise-grade cloud infrastructure with physical security controls, network segmentation, and DDoS protection. All data at rest is encrypted using AES-256 and data in transit is protected via TLS 1.2 or higher.

Monitoring & Threat Detection

Our systems employ continuous monitoring and anomaly detection. Security logs are retained for a minimum of 12 months. Suspicious activity is automatically flagged for investigation by our security operations team.

Data Privacy & Compliance

We process personal data in accordance with UK GDPR and the Data Protection Act 2018. Data minimisation principles are applied throughout. We do not sell or share personal data with third parties for marketing purposes.

Business Continuity

Regular automated backups ensure data integrity and rapid recovery in the event of system failure. Recovery Point Objective (RPO) and Recovery Time Objective (RTO) targets are tested periodically to ensure operational resilience.

Vulnerability Management

We conduct periodic security assessments and code reviews. Identified vulnerabilities are triaged and remediated in accordance with their severity. Critical patches are applied within 48 hours of discovery.

Gateway & Financial Data Security

Postback Validation. All inbound server-to-server postbacks from partner systems are validated using an HMAC shared secret. Unsigned or incorrectly signed postbacks are rejected and logged for audit.

Commission Ledger Integrity. Conversion and invoice records are treated as an immutable financial ledger. Rate snapshots are taken at conversion time and cannot be retroactively modified. All reconciliation runs are logged with timestamps.

Invoice Document Storage. Generated invoice PDFs are stored in a private, access-controlled file store. Temporary signed URLs with short expiry windows are issued for authorised downloads — files are never stored in or served from a publicly accessible location.

Vendor Vetting & Data Isolation

Pre-Vetting Process. Every software vendor listed on the Nexus Hub undergoes an automated pre-vetting screening against ten criteria — including agentic-AI capability, enterprise readiness, and affiliate-program standing — before a human analyst review. Vendors that do not meet our standards are deprioritised and never onboarded.

Three-Way Audit Loop. Vetting findings are validated through a three-way audit loop combining human analyst evidence, an independent AI verification pass, and analyst resolution of disagreements, producing a confidence score for every case and keeping the marketplace catalogue trustworthy.

Row-Level Data Isolation. Company profiles and member data are isolated by verified email domain using row-level security. Users can only read and update the shared company profile for their own organisation; private member fields such as role and preferences remain visible only to the individual member.

Link Health Monitoring. Product URLs across the marketplace are checked on a configurable schedule so broken links and missing data are detected and remediated before they reach buyers.

Responsible Disclosure

If you believe you have discovered a security vulnerability in our platform, we encourage responsible disclosure. Please contact us immediately at info@omniagentics.net with a description of the issue and steps to reproduce it. We commit to acknowledging your report within 48 hours and working towards a resolution in a reasonable timeframe.

Please do not publicly disclose a vulnerability before we have had the opportunity to investigate and address it.

Contact

For security-related enquiries, please contact us at info@omniagentics.net. For general enquiries, please visit our Contact page.

Version 2.0 — Last updated: 22 August 2026 — Omniagentics Limited, 66 Paul St, London EC2A 4NA, United Kingdom.

Cookies & storage

We use cookieless traffic analytics by default. Optional analytics cookies help us understand form outcomes and company-level interest. Essential storage keeps the site working.