Omnafy

White papers

Four papers on governing AI access to the systems your business runs on. Each is written for a different reader, each states what is built and what is only designed, and each ends with the limits rather than a summary. Start with the security paper; it fixes the vocabulary the other three use.

Security and compliance leaders

Governing AI access to systems of record

The Omnafy security and governance architecture

A new employee gets an account, a role, a manager, and a paper trail before they touch a system of record. An AI caller gets an API key and a hope. This paper describes the architecture that closes the gap: five named invariants, two trust boundaries with an enumerable seam, an identity model with no anonymous path, two redundant enforcement points, an append-only attributable record, and a published list of the risks we accept rather than mitigate.

Version 1.0 · August 31, 2026 · 30 min read

Architects and technical evaluators

The Omnafy platform architecture

An MCP gateway with governance in the request path

Anything beside the request path can be routed around, and anything that can be routed around is not a control. This paper is the engineering description of a system that puts governance in the path: why MCP is the universal interface, how five planes divide responsibility, what the gateway does between receiving a call and returning a result, how the scope algebra stays computable, and how the whole thing splits across two cloud accounts.

Version 1.0 · August 31, 2026 · 35 min read

Operations leaders

Earned autonomy

Risk tiers, approval queues, and how supervision ends

Every organization that puts a human in the loop finds the same two failure modes: the queue is a bottleneck, and then the queue is a rubber stamp. This paper describes the design against both. Risk is classified per tool, approvals carry mandatory evidence, and autonomy is earned per identity and task on measured evidence, with automatic demotion when quality slips. One category never graduates.

Version 1.0 · August 31, 2026 · 25 min read

Compliance officers and auditors

HIPAA and the AI governance layer

Omnafy's compliance posture, pre-certification

Omnafy holds no SOC 2 report and has engaged no auditor, and HIPAA has no certification regime at all, so this paper describes design posture and readiness rather than attestation. It maps the architecture onto Security Rule obligations, states the business associate agreement chain, assigns responsibility per control family, gives the retention and deletion lifecycle in full, and names the gap a Type II examination would still have to close.

Version 1.0 · August 31, 2026 · 25 min read

What is not in these papers

These papers summarize a larger internal documentation set: the full threat model with all ten scenarios written out, the audit events contract with its schemas, the tool-server contract every adapter is built against, the policy schema, and the decision log behind every architectural choice. Customers, prospective customers, and their auditors can request the whole set.

If you are evaluating us and want the adversarial review before the pitch, ask for the threat model. We wrote it before anyone asked.

Write to hello@omnafy.com.