Trust and security
OmniLore combines identity, least privilege, separated workspaces, explicit confirmation, isolated jobs, and evidence. These controls reduce risk; they do not justify a claim of perfect security.
Identity and admission
Chat, RepoHub, and organization mail require an admitted account. A pending or disabled account is denied even when an old password hash might otherwise validate.
Permissioned tools
Tools are filtered by the signed-in member, role, workspace, and current feature policy. Consequential actions can require confirmation. A denial should fail closed rather than silently broadening access.
Separated work
Personal conversations, session summaries, connected sources, and workspaces are not ordinary cross-member search. Approved administrators retain limited support, recovery, security, and lawful-access paths.
Isolated code jobs
Approved developer projects can run named checks in a dedicated environment without internet, Docker, Chat secrets, or other member workspaces. Successful code claims require a durable result receipt. Chat is not a free shell or full debugger.
Connections and local-first work
CoTrinity can keep ordinary coding work local, but OmniLore is not air-gapped. A connected request sends the required content to OmniLore services and any external provider the member explicitly uses.
Known limits
- The controlled beta is not certified as a universal compliance solution.
- Password recovery and emergency access remain sensitive operational paths.
- Third-party providers have separate security and privacy commitments.
- No system can promise perfect security or uninterrupted service.
Report a concern
Email abuse@omnilore.ai. Include the affected service, time, and a safe description. Do not send credentials, invitation tokens, exploit payloads containing secrets, or unnecessary personal data. See security.txt.
