How Omni protects your work.
Last updated September 8, 2026
Your Mac runs your agents. Your iPhone connects to that Mac. Omni protects this connection, while the agent’s permissions and your device security determine what it can access.
Encrypted between your devices
Paired message payloads use AES-256-GCM authenticated encryption over an HTTPS connection to the relay. The relay routes encrypted payloads; it does not have the paired phone’s key to decrypt them. It can see connection metadata such as routing identifiers, request sizes, timing, and network addresses.
The Mac decrypts requests and your chosen agent sends the information needed for its work to OpenAI, Anthropic, or connected tools. Device-to-device encryption does not hide that information from the services doing the work.
Pair only devices you trust
A pairing code contains a secret. It expires after five minutes and can be used once. Each paired phone receives its own credential. Never post the code or send it to support.
If a phone is lost or no longer trusted, remove it in Omni’s connection settings on the Mac. That prevents future requests from that credential. It does not erase data already downloaded, undo completed actions, or necessarily stop work already running.
Keys and local files
Omni stores device credentials in Apple Keychain and encrypts the Mac’s pairing records using a Keychain-held key. Chats, attachments, backups, and the native agent’s files are not all encrypted separately by Omni. Use a strong device passcode, enable FileVault on your Mac, and protect your backups.
Agents can act on your Mac
Omni uses the permissions and approval controls supplied by Codex and Claude Code. It does not add a separate security sandbox around them. Depending on those controls, an agent can read and change files, run commands, access the network, and use connected services.
Choose the autonomy level appropriate to the work. Full autonomy can allow actions without asking you. A bot’s written instructions are guidance, not an access-control boundary. Only connect accounts and tools you intend it to use, review sensitive work, and treat untrusted documents and websites as potential sources of misleading instructions.
Jobs can run when you are away while your Mac is awake and Omni is open. Review each job’s instructions and approval behavior before leaving it unattended.
Notification previews
The Mac encrypts notification content for the phone before passing it through the relay and Apple’s push service. The phone decrypts it for display. Your iOS settings control whether that preview appears on the lock screen.
Updates and reporting
Download Omni from this site or the linked TestFlight invitation. Mac releases are signed and notarized by Apple, and the built-in updater verifies signed updates. Keep Omni, your operating system, and your agent tools up to date.
To report a suspected vulnerability privately, email hello@2001.ventures with the subject “Omni security report.” Include the affected version, a description, and safe reproduction steps. Do not include live credentials, private conversations, or other people’s information.
For data handling, analytics choices, and deletion requests, read our privacy policy.