Your documents stay yours.
Ohmix turns your workshop manuals into a private diagnostic knowledge base. This page states plainly how that data is handled — and what we have not yet certified.
Last updated 13 Aug 2026 · questions: security@ohmix.eu
Data ownership & isolation
The manuals and case data you upload remain yours. You can export or delete them at any time.
Each organisation's data is scoped to that organisation. Access is enforced at the database layer with row-level security on every customer-data table and on file storage — not only in the UI — and verified by a negative isolation test suite before schema promotion.
In transit via TLS/HTTPS (HSTS enabled). At rest through our storage and database providers' encryption. Documents are served only through short-lived signed links to signed-in members.
Sign-in is per named person, by password or by a one-time email link — your choice at sign-in. Organisation roles: owner, admin, service manager, technician, trainer, billing manager, read-only reviewer. Nobody can raise their own role; platform staff roles are separate and cannot be self-granted.
Subprocessors
We use a small number of vetted providers for hosting, transactional email, payment and the AI processing that turns your documents into answers. Every one of them is named — with what it does, what data it receives and where it processes — in the sub-processor register in our Data Processing Agreement.
That register is the single place we keep this list. It used to be duplicated here, and the copy fell behind the system: four providers were in production and not on this page. One list, in one place, is the only version of this that stays true.
In every case, only the retrieved excerpts and evidence needed for the request are sent — processing is per-request and server-side; providers never receive your library wholesale, and none of them holds it on a standing basis. Where a provider is outside the EEA, the transfer basis is stated for each one.
Your documents and file storage stay in the EU: database, storage and our server-side functions all run in Ireland.
Verified honesty — enforced, not promised
A manual is only marked “indexed” when its searchable index verifiably reaches the last page of the document. A truncated index fails loudly and is never presented as complete.
Every technical value is validated against the cited page before it reaches a report. Unsupported figures are withheld, and “the sources do not state this” is a first-class answer.
A part replacement is authorised only when a confirming technician measurement exists — enforced server-side, never by the model's own claim.
Workshop memory learns only from repairs a human confirmed, is isolated per organisation and per vehicle model, and can never invent page numbers or specifications. There is no self-modifying AI.
AI-training policy
Your documents and case data are not used to train Ohmix models or shared to train third-party foundation models. AI is used only to answer your questions from your sources, server-side.
Retention, deletion & export
- You can export your organisation's data at any time while your workspace is open.
- Deletion removes both database records and stored files (durable deletes, no silent resurrection). It is refused only while a document is still cited by a report that has not been withdrawn, so a published report cannot silently lose its evidence.
- After the service ends we delete your data on request, with no waiting period. If you make no request it stays available, so a cancellation made in error does not cost you your library.
- Two things survive that deletion, and we name them rather than leave them implied: audit events reduced to actor, action and time; and invoices, for the period Italian law requires of accounting records.
The full position is in the Data Processing Agreement and the privacy notice.
Restricted documentation
Some brands' documentation is restricted: uploads for them are refused server-side unless Ohmix has recorded an explicit authorization grant for your organisation (for example, verified OEM-authorized dealers). Every upload additionally requires a recorded, versioned authorization confirmation from the uploader, and every document open is written to an append-only audit trail.
What is not in place yet
- No formal certification (ISO 27001 / SOC 2) — practices are GDPR-aligned but not independently audited.
- No independent penetration test has been carried out yet.
- No contractual uptime commitment and no formal incident-response SLA. We commit to a 48-hour breach notification to customers in the Data Processing Agreement; that is a different and narrower thing than an availability SLA.
- The database is backed up daily and about a week is retained. Point-in-time recovery is not enabled, so a database restore recovers to the last nightly backup and could lose up to a day of work.
- Your uploaded documents live in object storage, which those database backups do not cover — enabling point-in-time recovery on the database would not extend to them. Keep your own copies of anything you could not obtain again. The measures annex sets out what is protected by what.
Removed from this list on 13 Aug 2026, because they had become untrue rather than because they were fixed quietly: the ingestion and engine workers are no longer "being provisioned" — they have been running in production for weeks; and self-serve payment is being switched on, so "nothing is charged without a signed agreement" no longer describes the product. Both are recorded here rather than deleted, because a trust page that edits its own history is not one.
Reporting a concern
Security issue or data request: security@ohmix.eu. We aim to acknowledge within two business days.