Documentation hub of the OmniFlow SaaS service: the complete user help for every module (public, no registration needed), the REST API documentation for developers, and an overview of the service security principles.
Practical guides for every module — from your first invoice through inventory and bank matching to company settings. Public, in Czech, Slovak and English, continuously updated with every new feature.
OmniFlow has a modern REST API for connecting an e-shop, accounting software or reporting: API keys with granular permissions, reading contacts, products and stock levels. The documentation with a test console is public (in English).
Open the API documentationOmniFlow is a cloud invoicing, payables and stock application for Czech businesses. OmniFlow is operated by OmniSys s.r.o. You use the service in a browser (SaaS); your company data is stored in the service’s secure infrastructure.
One user account may access multiple companies (e.g. parent and subsidiary, or several trades). Company data is separated; you only see companies you were granted access to. Switch the active company from the sidebar.
Customers and suppliers (contacts) always belong to the active company – they are not shared across all OmniFlow customers globally; each of your companies has its own directory.
Each area of the app is described in detail in the user help (links above) — it is public, so you can read it even before creating an account.
At OmniSys, data security and product quality are top priorities. We run OmniFlow as a professional SaaS service with continuous maintenance, monitoring, and secure operating practices.
Access and identity
• secure session-based sign-in,
• strict company and customer-account data separation,
• all user operations run in active tenant context.
Account protection
• one-way password hashing (bcrypt),
• CSRF protection on state-changing requests,
• login attempt limits to reduce automated abuse,
• mandatory two-factor sign-in (2FA) — e-mail code or Authenticator; TOTP secrets and backup codes stored securely (encryption, one-time recovery codes).
Credential recovery
• password change/reset via time-limited links,
• optional session invalidation after sensitive security events.
Operational security
• HTTPS transport,
• regular infrastructure/dependency patching,
• monitoring and logs used for timely incident response.
Security detail note: internal control parameters are intentionally not published publicly to avoid helping attackers.
How do I switch documentation language?
Use the CS/EN switch in the header of the documentation page.
Why do different users see different actions?
Feature visibility and available actions depend on user role and licence state.
Can one account manage multiple companies?
Yes. A single account can access multiple companies and switch active context.
Where can I find privacy and data processing information?
On the Privacy page (`/privacy`).
How do backups and data restore work?
We keep daily backups with a 30-day retention window. Data restore is available for a fee to a selected date within the available backup window.
Do you publish internal security configuration details?
No. Public documentation covers principles, not internal protection parameters.
Links: Privacy policy — in the app at /privacy or https://omniflow.cz/en/privacy. Terms of service: https://omniflow.cz/en/vop. Legal overview: https://omniflow.cz/en/legal.
This documentation is not legal advice. For tax and legal conclusions consult a professional.