Why Omnira
Spend less. Run less. Expose less.
Omnira™ runs your software on machines you already own — and leaves nothing on them: a job opens in a sealed vault in memory, runs, and is gone.
compute comes from machines you already own.
Running the serviceup to 50% lessno machine to manage, nothing to patch, no one to page.
Attack surface90% smaller9 of 10 elements removed or handled.
Ways data and IP can leak95.5% fewer10 of 11 paths removed, and network traffic encrypted.
The two cost figures are estimates from our own modelling; the two security figures count the elements and paths listed below. They are not measurements of your systems and not a warranty. What you save depends on what you run and where it runs today. Omnira is an early product, priced as one — see the terms.
Where the saving comes from
The cloud bill. Work that ran on rented machines runs on the servers, desktops and devices you already own and already power. You keep the cloud for what genuinely needs it.
Running the service. There is no fleet of hosts to provision, patch, harden and watch. You hand over the service; the platform places it, moves it when a machine goes away, and keeps it serving.
Less to attack
A conventional host gives an attacker a long-lived machine: an operating system to keep patched, a disk that remembers, credentials that sit still, and a network address that answers. Omnira removes most of that shape. Your service runs inside a sealed vault in memory on a device that opens no port to the internet, keeps nothing after the job, and holds no standing credential.
Fewer things that can be reached, and fewer that persist, is the whole of it.
90% smaller attack surface: 9 of 10 elements removed or handled
Today: 8 of 10 at risk · 2 may be at risk*
Inbound listenersToday: At riskWith Omnira: Removed
What it is. Open network ports where software waits for incoming connections: web servers, databases, management agents.
Today: Every open port is a door. Attackers scan the internet for them and break in through the software behind them.
With Omnira: Omnira opens no network port on the server, so there is nothing on it for a scanner to find.
Remote administrationToday: At riskWith Omnira: Removed
What it is. Ways for people to log in to the server: SSH, remote desktop, management consoles.
Today: Logins are a favourite target: a stolen password or key gives an attacker the same control as an administrator.
With Omnira: Running a job needs no login to the server. You publish to your hub and the hub sends the work, so no one needs an account on the machine to run your services.
Local artifactsToday: At riskWith Omnira: Removed
What it is. Software installed on the server’s disk: programs, packages, libraries and configuration files.
Today: Installed software stays on the disk after the job, where anyone who reaches the machine can copy it, study it or change it.
With Omnira: A service’s code streams into RAM, encrypted, and runs from there. Nothing is installed on the disk, so nothing is left behind when the job ends.
Persistent host identityToday: At riskWith Omnira: Removed
What it is. Long-lived secrets kept on the server: SSH keys, cloud credentials, service passwords and tokens.
Today: Copied once, they keep working: an attacker can use them from anywhere, long after leaving the machine.
With Omnira: No credential for your storage or your code is stored on the server’s disk. What a job needs is held in memory, for that job only.
Host logsToday: At riskWith Omnira: Removed
What it is. Records the server keeps of what ran, when, and what it touched.
Today: Logs often hold names, addresses, queries and even data, and they stay on the disk long after the job.
With Omnira: Your services’ logs go straight to your own storage. The server’s own system logs record no job data.
Disk snapshotsToday: At riskWith Omnira: Removed
What it is. Copies of a server’s disks, taken for backup, recovery or migration.
Today: A snapshot carries everything on the disk to wherever it is kept, often to more people and places than the server itself.
With Omnira: The disk never holds job data, so its snapshots hold none.
Network in transitToday: May be at risk*With Omnira: Encrypted
What it is. Data moving between the server, your storage and your users.
Today: Traffic that is not encrypted can be read or changed on the way. Counted as half: it depends on how a network is set up.
With Omnira: Everything between your storage, your hub and the server is encrypted, in both directions.
Control planeToday: At riskWith Omnira: No job data
What it is. The system that decides which machine runs which job and manages the machines. In Omnira, that is your hub.
Today: A control plane that stores job data is one place to steal all of it from.
With Omnira: Your hub places jobs and passes their traffic, but keeps no job data. In a sovereign Omnira, you run the hub yourself, on infrastructure you choose.
OS and firmwareToday: At riskWith Omnira: No data at rest
What it is. The operating system and the low-level software that start and run the machine.
Today: A compromised operating system sees everything stored on the disk.
With Omnira: There is no job data on the disk for it to find: a job’s data exists only in memory, while the job runs.
Data in useToday: May be at risk*With Omnira: Operator-blind*
What it is. Data in memory while a job runs. On any computer, data has to be in memory to be worked on.
Today: Someone with full control of a machine can, with effort, read its memory. Counted as half: it depends on who controls the machine.
With Omnira: In memory only for the length of the job, never on disk, and Omnira gives the machine’s owner no login, file or log that shows it. Memory-encrypting chips, which protect it even from someone with full control of the machine, are on our roadmap.
Less exposed
Running on someone else’s infrastructure means your code and your data are readable by whoever operates it — their staff, their tooling, their logs, their subpoenas. On Omnira your service runs on hardware you choose, and what it handles is sealed while it runs and gone when it stops.
Your code stays yours. So does what it touches.
95.5% fewer ways to leak: 10 of 11 paths removed, and network traffic encrypted
Today: 10 of 11 at risk · 1 may be at risk*
Data at restToday: At riskWith Omnira: Removed
What it is. Job data saved on the server’s disks.
Today: Whatever is saved stays until someone deletes it, and anyone who reaches the disk can read it.
With Omnira: No job data is written to the server’s disk. A job reads from and writes to your own storage.
Code and model weights on diskToday: At riskWith Omnira: Removed
What it is. Your proprietary code and trained model weights, copied onto the server so it can run them.
Today: Once on a disk, your intellectual property can be copied in seconds and studied at leisure.
With Omnira: Streamed into RAM, encrypted, from your own storage, and never written to the disk.
Crash dumps and swapToday: At riskWith Omnira: Removed
What it is. Memory the system writes to disk when a program crashes or memory runs short.
Today: A crash dump or a swap file can hold a running job’s data and secrets, written to disk without anyone asking.
With Omnira: Set up as Omnira asks, with no swap and crash dumps off for its runner, memory never spills to disk. The Traceless Compute Proof checks both on the machine it runs on.
Temp and cache filesToday: At riskWith Omnira: Removed
What it is. Short-lived files that programs write while they work.
Today: Temporary files are forgotten more often than deleted, and they can hold pieces of the data a job worked on.
With Omnira: A service’s working folder and temporary files live in RAM and end with the job.
Host logs and telemetryToday: At riskWith Omnira: Removed
What it is. Records and metrics on the server about what ran and what it touched.
Today: They stay on the disk, and are often shipped to more places than the job’s own data.
With Omnira: Your services’ logs go straight to your own storage. The server’s own system logs record no job data.
Snapshots and backupsToday: At riskWith Omnira: Removed
What it is. Copies of a server’s disks made for backup, recovery or migration.
Today: Backups outlive the server, and are kept in more places than the server itself.
With Omnira: The disk holds no job data, so its copies hold none.
Keys stored on the hostToday: At riskWith Omnira: Removed
What it is. Encryption keys and credentials saved on the machine.
Today: A key on a disk unlocks your data wherever the disk is taken.
With Omnira: No key to your storage or your code is stored on the machine, so your data stays locked without your key.
Retired hardwareToday: At riskWith Omnira: Removed
What it is. Old disks that are resold, recycled, returned or lost.
Today: Deleted data can often be recovered from a disk that leaves the building.
With Omnira: Retired disks never held job data, so they leak none.
Operator access to stored dataToday: At riskWith Omnira: Removed
What it is. Staff of the server’s owner, or of its cloud, reading data on its disks.
Today: Whoever runs a machine can read what is stored on it.
With Omnira: The disks hold no job data to read, and Omnira gives the machine’s owner no login, file or log that shows a job.
Legal demands on stored dataToday: At riskWith Omnira: Removed
What it is. Orders to hand over data held on a server, sent to whoever owns or runs it.
Today: Data stored on someone else’s machine can be handed over without you knowing.
With Omnira: The server holds no job data to hand over: your data is in your own storage, with you.
Network interceptionToday: May be at risk*With Omnira: Encrypted
What it is. Data read while it moves between the server and your storage.
Today: Traffic that is not encrypted can be read on the way. Counted as half: it depends on how a network is set up.
With Omnira: Encrypted in both directions, between your storage, your hub and the server.
* May be at risk, depending on setup. Counted as half. Data in use is the one element that stays: a job needs its data in memory while it runs, so it can never be removed. With Omnira it is in memory only for the job and never on disk; memory-encrypting chips, which protect it even from someone with full control of the machine, are on our roadmap.