Omnia File Analysis logo
Privacy Security · Security Code Scanning

Omnia File Analysis

File-inspection capability inside the Omnia AI security platform. Upload a binary, script or document and it is analysed automatically, opened in a hexadecimal view, and turned into a YARA detection rule with AI assistance.

Active GDPR compliant API available 14+ Verified by Guidaio
Overview

What is Omnia File Analysis?

Omnia File Analysis is the file-inspection capability inside Omnia, an AI security platform built by Synthwise S.L., trading as OmniaSec AI, a small team from the University of Málaga in southern Spain. It is neither sold nor documented as a standalone product: it is one of four capability areas presented on the platform's homepage, alongside conversational analysis, marketplace monitoring and workflow automation.

The premise is straightforward. You drop a file into a conversation and the platform analyses it automatically, then presents its findings in the interface. The publisher claims decompilation of binaries, disassembly of code, and detection of obfuscated malware and zero-day patterns that conventional scanners miss. Submitted artefacts may be files, scripts, documents or binaries; they are unpacked, decompiled, disassembled and correlated against external intelligence sources.

What distinguishes the module is what happens after that first pass. Every uploaded file lands in a file panel beside the conversation. Selecting an executable opens a hexadecimal view exposing raw byte content, embedded strings and patterns, and structural elements relevant to malware analysis. From that same view an analyst can highlight a region of hex and ask the platform to generate a YARA rule from it, with the model drawing on both the selected bytes and the surrounding analysis context. The publisher's stated aim is that nothing leaves the workspace: no exporting, no external tools.

Supporting utilities sit around this loop. Archives, including password-protected ones, can be extracted; raw bytes, text and file metadata can be read; Python runs in a secure sandbox; structured reports are generated with source attribution. Two official connectors, VirusTotal and a YARA-X server, are enabled with a toggle, and analysts may attach their own Model Context Protocol servers without redeployment.

Because it lives inside a broader platform, the module inherits custom agents, reusable prompt templates, private knowledge bases, scheduled tasks and a community library of shareable workflows. Access is through the web application, an installable command-line client for macOS and Linux, or an API with a public Python SDK. Two gaps are structural rather than incidental: the publisher issues no terms of service, publishes no pricing, and claims no security certification.

What it does

  • Upload a file and receive an automatic analysis inside the conversation
  • Open an uploaded binary in a hexadecimal view to inspect raw bytes and embedded strings
  • Generate a YARA detection rule from a selected region of hexadecimal data
  • Deobfuscate layered scripts and have the underlying logic explained
  • Look up a hash across multiple detection engines and intelligence platforms
  • Extract compressed archives, including password-protected ones
  • Produce a documented threat report with source attribution
Audience

When to use Omnia File Analysis / When not to

A quick filter to help you decide if Omnia File Analysis is the right fit.

When to use Omnia File Analysis

  • Malware analysts who want to move from a sample to a detection rule without leaving the workspace
  • SOC and incident-response teams triaging suspicious attachments and binaries under time pressure
  • Security researchers, for whom the publisher deliberately keeps guardrails minimal
  • Small teams with no in-house reverse-engineering tooling or budget for a commercial sandbox
  • Students and newcomers to reverse engineering, who are promised clear, jargon-free explanations

When not to use Omnia File Analysis

  • Organisations that need a contract: the publisher issues no terms of service and no data processing agreement
  • Anyone handling regulated or sensitive data, whom the privacy policy itself tells to think twice before sending it
  • Buyers who require a security certification, since neither SOC 2 nor ISO 27001 is claimed anywhere
  • Teams that need a service level agreement or contractual support, as a single mailbox serves every request
  • Users looking for an offline or self-hosted scanner, as no on-premise deployment is documented
Get started

How to use Omnia File Analysis

A typical end-to-end flow, from setup to results.

  1. Create an account on the web application by signing in with Google, GitHub, X or Facebook; no password is created
  2. Alternatively, open a case someone has shared publicly, which requires no account at all
  3. Start a conversation and upload the file you want examined, for instance an executable
  4. Let the automatic analysis run and read the findings returned in the interface
  5. Find the file in the file panel on the right of the screen and select it
  6. Open the hexadecimal view to inspect raw bytes, embedded strings and structural elements
  7. Select a portion of the hexadecimal data and choose Create YARA rule to draft a detection signature
  8. Toggle on the connectors you need, such as VirusTotal or a YARA-X server, or attach your own MCP server
  9. Use the Connector button in the message box to see which tools and methods are currently active
  10. For repeat work, install the command-line client or use the Python SDK with an API key
Quick read

Pros & Cons

Pros

  • The whole chain lives in one context: sample, hexadecimal inspection and YARA rule without exporting anything
  • Unusual transparency, with the agent's system prompt published and minimal guardrails openly acknowledged
  • Open connector model: users attach their own MCP servers without waiting for a redeployment
  • Three ways in, namely a web application, a command-line client and an API with a public Python SDK
  • European publisher operating explicitly under the GDPR and the Spanish LOPDGDD, with EU hosting as a stated aim
  • Genuine user control over history, which can be deleted conversation by conversation or in full
  • A vulnerability disclosure programme with an explicit safe harbour for good-faith research

Cons

  • No terms of service at all: the site publishes none, confirmed against its full sitemap
  • No published pricing of any kind, so the commercial model is impossible to assess
  • No security certification is claimed, neither SOC 2 nor ISO 27001
  • No named list of subprocessors and no data processing agreement offered
  • The publisher states it has no funding, which raises a question over long-term continuity
  • A single mailbox handles legal, GDPR, support and security matters for a self-described small team
  • Product documentation is thin: the detail of the file-analysis module lives mainly in one blog post
Pricing

Pricing & Plans

Omnia publishes no pricing. There is no pricing page on the site, no amount anywhere in its pages or in its web application, and the /pricing and /plans URLs return HTTP 404. Access is obtained by signing in with a Google, GitHub, X or Facebook account, and no payment is requested at registration. On its vulnerability disclosure page the publisher states that it has no funding and cannot pay cash rewards. Consequently no starting price, currency or billing unit is recorded for this tool: the absence of a figure reflects the absence of published pricing, not a gap in collection.

Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Omnia File Analysis handles your data.

GDPR overview

GDPR implementation is explicit and reasonably detailed for a project of this size. The privacy policy, last updated 1 October 2025, names Synthwise S.L. as controller, states that the service operates under the GDPR and the Spanish LOPDGDD, and lists a legal basis for each processing purpose. Users are told they may access, rectify, erase, port, restrict or object to processing and withdraw consent, by writing to info@omniasec.ai or using in-product controls, with a right of complaint to the Spanish supervisory authority, the AEPD. The minimum age is 14, the Spanish age of digital consent. Only essential cookies run by default. Transfers outside the EEA are covered by Standard Contractual Clauses. No Article 27 representative is named, which is consistent with an EU-established controller.

Who owns the data?

The controller is Synthwise S.L., trading as OmniaSec AI. The privacy policy states that conversations and any files sent for analysis are collected, alongside an account email, usage and security logs, and whatever the user chooses to publish to the community. Ownership is not transferred: chat history is kept per user and can be deleted conversation by conversation or in full from the application, and community items are private by default with visibility chosen by the user. Unpublishing is possible, though copies already forked or downloaded by others may persist. The publisher states plainly that it does not sell personal data.

Reuse rights

Processing rests on four declared legal bases: contract for delivering the service, consent for community visibility choices, legitimate interests for security and for improving Omnia, and legal obligation. Users may reuse and redistribute what the community publishes: the platform is built around forking, remixing and contributing back agents, workflows, prompts, knowledge bases and MCP connectors, and items published under a public setting are explicitly meant to be taken and modified. Third-party connectors receive data only when the user invokes them, and that provider then acts under its own terms as an independent controller or processor. Submitting a vulnerability report grants the publisher the right to use it to improve Omnia. Notably, the policy never addresses whether uploaded content is used to train models.

Data retention & training

Retention summary
Retention is described by category. Your account is kept until you delete it. Chats and the files you upload are kept until you delete them individually or delete the account. Security and usage logs are typically kept for twelve months, extending to twenty-four months for serious security incidents. Backups are time-limited and encrypted, with items purged on a rolling cycle, so deleted material leaves active systems first and backups afterwards. The publisher states that data is kept only as long as needed for the stated purposes or to meet legal requirements. Deletion controls are available in the application, conversation by conversation or in full. No anonymisation or pseudonymisation practice is described.
Trains on customer data
Unclear
GDPR contact

Hosting summary

The publisher is established in Spain and operates under the GDPR and the Spanish LOPDGDD, with the AEPD as supervisory authority. On hosting itself, the wording is deliberately conditional rather than a commitment: it aims to host in the EU or EEA where feasible, and acknowledges that some processors or connectors may operate outside the EEA. Where transfers do occur, they are covered by EU Standard Contractual Clauses with additional safeguards where required. No hosting country is named and no hosting provider is identified. Processors are described only by category, namely hosting, storage, email, error logging and optional analytics, engaged under Article 28 contracts. Security measures claimed are encryption in transit and at rest, access controls, least privilege, monitoring and regular reviews. Readers should treat European hosting as an intention stated by the publisher rather than as a guarantee, and should note that invoking any third-party connector moves data outside this perimeter by design.

Hosting regions
EU
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Omnia File Analysis.

  • Uploading a real malware sample to a third-party service is an act with consequences: the analyst, not the platform, carries responsibility for what leaves the organisation
  • Data reaches an outside provider the moment a connector is invoked, and that provider then operates under its own terms as an independent controller or processor
  • The publisher's own advice deserves repeating: review a connector's privacy terms before use and, if in doubt about sensitive or regulated data, do not send it
  • Guardrails are minimal by design, so prompt manipulation is treated as expected behaviour rather than as a defect to be fixed
  • With no terms of service, the relationship with the user is not contractually defined, which matters when something goes wrong
  • Community publishing is reversible, but copies already forked or downloaded by others may survive an unpublish
  • An AI-generated YARA rule is a draft, not a verdict: accepting it without reading the bytes it came from erodes exactly the skill the tool is meant to support
Setup

Setup & Integrations

Technical difficulty

Getting started is easy. The web application needs no installation: you sign in with a Google, GitHub, X or Facebook account, with no password to create, and you can upload a file immediately. Official connectors are enabled with a single toggle. Difficulty rises with ambition. Attaching your own MCP server, using the API or installing the command-line client assumes technical confidence, and the command-line installer covers macOS and Linux only. Above all, reading hexadecimal and judging a YARA rule are analyst skills that the interface makes faster but does not replace.

Deployment

Web appAPI

Integrations

VirusTotal YARA X Server Google GitHub X Facebook

Supported languages

English
Company

Behind Omnia File Analysis

Company name
Synthwise S.L.
Founded
INFORMATION_NOT_FOUND
Country of origin
🇪🇸 Spain
Headquarters
Málaga (Spain)
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇺🇸 United States
Legal contact
Support contact

Social

Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

What kinds of files can Omnia analyse?
Files, scripts, documents and binaries. The publisher gives executables as its worked example and describes unpacking, decompiling and disassembling them. No limit on file size or accepted formats is published anywhere on the site.
What happens after I upload a file?
Omnia analyses it automatically and presents the results inside the platform. The file is then added to the file directory panel on the right of the interface, where deeper inspection begins.
Can I inspect a binary at a low level?
Yes. Clicking an executable in the file panel opens a hexadecimal view that exposes raw byte content, embedded strings and patterns, and structural elements relevant to malware analysis.
Can Omnia write detection rules for me?
Yes. From the hexadecimal view you select a portion of the data and choose Create YARA rule. The rule is generated with AI assistance, drawing on both the selected bytes and the analysis context, and you keep control over the result.
Which third-party services does it connect to?
VirusTotal and a YARA-X server are offered as official connectors enabled by a toggle. Beyond those, you can add and manage your own Model Context Protocol servers without any redeployment.
How much does it cost?
No price is published. The site has no pricing page and no amount appears anywhere on it. Access is obtained by signing in with a Google, GitHub, X or Facebook account, and no payment is requested when registering.
Is there an API?
Yes. The API is served from api.omniasec.ai and the publisher maintains a public Python SDK installable with pip. The interactive API documentation itself is protected and requires an API key to open.
Are my uploaded files used to train AI models?
The privacy policy does not address this question. It states that files sent for analysis are collected and lists improving Omnia as a purpose based on legitimate interests, but model training is mentioned nowhere. Treat the point as unresolved.
How long is my data kept?
Your account is kept until you delete it, and chats and files until you delete them or the account. Security and usage logs are typically kept for twelve months, extending to twenty-four for serious security incidents. Backups are encrypted and purged on a rolling cycle.
Who is behind Omnia, and are there terms of service?
The publisher is Synthwise S.L., trading as OmniaSec AI, a small team from the University of Málaga in Spain. The site publishes a privacy policy and a vulnerability disclosure page, but no terms of service.
Conclusion

Should you pick Omnia File Analysis?

Omnia File Analysis is a coherent answer to a real irritation in malware work: the distance between looking at a sample and shipping a detection rule. Uploading a binary, reading it in hexadecimal and generating a YARA rule from a selected region, all without leaving the conversation, is a genuinely useful loop, and the surrounding platform adds agents, workflows, scheduled tasks and a community library that make it more than a one-shot scanner. The openness is deliberate and, for research purposes, welcome: the system prompt is published, guardrails are kept minimal on purpose, and analysts can attach their own connectors.

The reservations are equally clear, and they are about maturity rather than about the idea. This is a young project out of a university setting whose publisher openly says it has no funding. There are no terms of service, no published pricing, no security certification, no named subprocessors and no data processing agreement. The privacy policy is unusually candid for a team this size, but it is silent on whether uploaded content is used to train models, which is an awkward silence for a service that invites you to send it malware samples.

Who should try it: malware analysts, SOC and DFIR practitioners, security researchers, and students learning reverse engineering, particularly those without access to expensive commercial tooling. Who should wait: anyone who needs a contract, a certification or an assurance about where their samples end up. The publisher itself gives the soundest advice on this point, telling users to review the terms of any connector they invoke and, if in doubt, not to send the data at all. Treated as a research and triage workbench rather than as a system of record, it earns its place.