Everything you know about your business ends up in this one system — who your customers are, what they buy, what they pay, and what you make. It is the memory of the business, and you are about to hand it to a vendor you have known for a few weeks. That is a lot of trust, and most buyers never ask the questions that would test whether it is deserved. This is a checklist for that conversation — vendor-neutral, useful against anyone you are evaluating, including us.
The questions that matter
You do not need to be technical to ask these. You need to listen for whether the answer is specific or evasive:
- Is my data isolated from other customers' data — and what enforces that separation, not just as a policy but in the system itself?
- Can I get all of my data out, on demand, in a usable format — or am I locked in once I am in?
- Who on my team can see and do what? Is access controlled by role, so the counter staff and the owner do not have the same reach?
- How do you protect an account from being taken over — is multi-factor authentication available, and are sensitive actions recorded?
- Is there an audit trail of who did what, so a mistake or a dispute can be traced?
- If I leave, what happens to my data, and how do I take my history with me?
What a good answer sounds like
A trustworthy vendor answers these plainly and without flinching. Isolation is enforced by the system, not promised in a sentence. Export is a feature you control, not a support ticket you file and hope. Access is role-based by default. Account protection and an audit trail are standard, not a premium tier. And leaving is treated as your right, with your history portable on the way out. Vague, defensive, or "trust us" answers to any of these are the signal to keep asking.
The vendor worth trusting is the one who answers "how do I get my data out and leave?" as calmly as "how do I sign up?"
How we answer our own checklist
It would be hollow to publish this and dodge it, so briefly: Omni isolates every tenant's data with enforcement built into the system rather than left to application logic; access is governed by roles and permissions so people see only what their job needs; accounts can be protected with multi-factor authentication; sensitive activity is recorded in an audit log; and your data is yours to export — the same portability that lets you bring your history in lets you take it out. We deliberately keep the description at the level of what we do and why it matters, not the internal mechanics — the point is that the protections are real and standard, not that we hand out a blueprint.
Trust is a decision you can test
You do not have to take data trust on faith. It is testable, with a handful of direct questions and a careful ear for how they are answered. Ask them of every vendor you consider — the answers will tell you quickly who treats your business's memory as yours, and who treats it as leverage. Get them before you commit, and you get to carry the thing few operators ever feel about their software: the quiet confidence that the memory of your business is safe, and it is yours.