OMNiGRC - Connected GRC Platform
SECURITY ARCHITECTURE & TRUST ASSURANCE

Transparent security boundaries. Human-governed AI.

OMNiGRC is engineered with application-level tenant isolation, advisory AI data minimization, and defensible audit trails to protect your organizational GRC telemetry.

VERIFIED SECURITY PRINCIPLES

Architectural Foundations

Clear technical parameters defining how OMNiGRC handles data, AI evaluation, and tenant isolation.

Application-Level Tenant Isolation

Logical data boundaries enforced at the application tier ensure strict authorization controls and data segregation between organization workspaces.

Workspace Scoped Boundaries

Advisory AI Data Minimization

Tenant-sensitive payloads and PII are stripped prior to AI clause correlation requests. AI outputs remain strictly advisory until explicitly approved by human analysts.

AI Assists, Humans Decide

Human-in-the-Loop Governance

Automated workflows generate recommendations, but all risk acceptances, control mappings, policy sign-offs, and evidence reviews require human confirmation.

Mandatory Human Sign-Off

External Evidence Index Model

Instead of copying sensitive customer files into platform storage, OMNiGRC indexes external reference links and metadata for auditor verification.

Reference Pointer Indexing

Event & Audit Traceability

Structured operational event logs record control changes, risk evaluation updates, and user actions for audit workpaper generation.

Auditing Workpaper Ready

Containerized Deployment Options

Flexible options for shared SaaS, private single-tenant MSSP instances, or customer-controlled container runtime environments.

Docker Container Support
DEPLOYMENT ARCHITECTURE

Deployment Models & Operational Boundaries

Accurate deployment classifications tailored to team infrastructure requirements.

MSSP_SHARED

Shared Multi-Tenant SaaS

Fast deployment for lean security teams with application-level tenant isolation, automated updates, and managed infrastructure operations.

  • Application-level workspace isolation
  • Managed maintenance & schema migrations
PRIVATE_MSSP

Dedicated Single-Tenant Instance

Dedicated application environment for managed service providers and enterprise teams requiring dedicated runtime boundaries.

  • Isolated application instance
  • MSSP multi-client context switching
SELF_HOSTED

Customer-Controlled Docker Runtime

Customer controls infrastructure and runtime operations, receiving Arav-distributed container artifacts for internal hosting.

  • Containerized Docker deployment
  • Internal infrastructure control
Self-Hosted Deployment Specification:"Under the Self-Hosted model, the customer controls infrastructure and runtime operations, but receives only Arav-distributed executable container artifacts, not the source repository or build/signing infrastructure."
PRODUCT TRUTH & BOUNDARIES

What We Do & Do Not Claim

What OMNiGRC Delivers

  • •Application-level tenant isolation boundaries
  • •Advisory AI suggestions requiring human approval
  • •5x5 likelihood x impact risk register scoring
  • •External evidence reference link indexing
  • •Vulnerability finding tracking from external sources

Non-Supported Marketing Overstatements

  • •No PostgreSQL RLS product guarantees
  • •No absolute "zero PII" guarantees
  • •No unsupported external certification sign-off or overclaimed audit chains
  • •No native vulnerability scanning claims
  • •No air-gapped LLM marketing claims

Discuss your security & architecture requirements.

Schedule a technical walkthrough to review tenant boundaries, advisory AI data minimization, and deployment options.

Request Architecture Walkthrough