HomeThe enterprise governance, risk & compliance operating system

About OnyxOne

OnyxOne is building the operating system for governance, risk and compliance — one platform where regulated organisations manage risk, controls, policies, obligations, audits, evidence and reporting. We are early, and we would rather be honest about that than manufacture a story.

Our mission

Compliance teams are asked to do more, with more scrutiny, on tooling that is fragmented across point solutions, spreadsheets and shared inboxes. The result is work that is hard to see, harder to audit, and slow to defend.

OnyxOne exists to make compliance operations feel as considered and dependable as the best enterprise software: one platform, one record, one workflow — with a defensible audit trail behind every decision.

The problem we're solving

Governance, risk and compliance has become one of the most consequential functions in a regulated business, and one of the worst-served by its tooling. A single programme is typically spread across a screening tool, a case tracker, a risk register in a spreadsheet, a policy library in a document store and an audit file assembled by hand. Data is copied between them, context is lost at every hop, and no single record shows the full history of a customer, a control or a decision.

The cost is not only inefficiency. When work lives in disconnected systems, evidence has to be reconstructed after the fact, oversight depends on whoever remembers where things are, and the answer to "how was this decided?" is a scramble rather than a record. That is precisely the question a regulator, an auditor or a board asks — and precisely where fragmented tooling fails.

One system of record

OnyxOne is built on a single premise: a governance, risk and compliance programme should run on one system of record, not a patchwork of point tools. Risk, controls, policy, obligations, audit, evidence, cases and reporting write to the same underlying record, so a decision, the evidence behind it and its place in the wider programme are never separated.

That is what turns compliance from a set of disconnected activities into an operating system — where every action feeds the next, oversight is continuous rather than periodic, and the audit trail is a by-product of doing the work rather than a project in its own right.

What we're building

A single, coherent platform where risk, controls, policies, obligations, audit, evidence, compliance cases and regulatory reporting operate together instead of in isolation.

Screening & due diligence
Sanctions, PEP and adverse-media screening wrapped in structured CDD, KYC, KYB and EDD workflows, mapped to your own risk policy.
Cases & investigations
Alerts routed into cases with evidence, entity links and recorded decisions — a defensible trail from alert to closure.
Governance, reporting & audit
Policy and controls, regulatory reporting, and an immutable audit trail so the whole programme is visible and defensible.

Where we sit

OnyxOne is the layer between your teams and your systems and data sources. Your teams work in one place; the platform centralises screening, cases and risk and connects to the systems of record and data providers your deployment requires.

How OnyxOne sits in your operationSchematic
Your teamsCompliance · risk · legalAnalysts & investigatorsScreen, review and decideOversight & approvalsSign-off and reportingOnyxOneCompliance & risk OSScreening · Due diligenceCases · Risk · MonitoringPolicy · Reporting · AuditSystems & sourcesConfigured per deploymentScreening data providersSanctions · PEP · mediaYour systems of recordOnboarding · core systemsOne platform for the whole programme — not a stack of disconnected tools and spreadsheets.

One platform for the whole compliance programme, connected to the systems and data sources your deployment requires.

How we build

  • Truthful by policy — no fabricated customers, metrics, certifications, endorsements or guarantees.
  • A vendor, honestly framed — OnyxOne is technology, not a regulated firm; your obligations remain yours.
  • Configurable, not prescriptive — the platform enforces your policy and risk model, not ours.
  • Honest empty states — where something isn't in place yet, we say so plainly rather than dress it up.
  • Built like critical infrastructure — server-only secrets, role-based access and audit-grade logging from day one.

The platform, honestly

OnyxOne runs on a deliberately conventional, dependable stack rather than anything exotic. The application is hosted and delivered on Vercel; data, authentication and storage run on Supabase; screening and data providers are configured per deployment. Sensitive keys stay on the server and never reach your browser.

High-level platform architectureSchematic
Your browserOnly ever receives the public anon key — never a secretVercel — edge delivery & hostingHTTPS/HSTS, cached SSR, hardened security headersApplication layer — server components & servicesServer-only secrets · role-based access · signed sessions · fail-safe integrationsSupabaseDatabase · auth · storageScreening & data providersConfigured per deploymentYour systems of recordIntegrated per deployment

A high-level view. Your browser only ever receives a public key; secrets and services run server-side.

Our legal entity

This website and the OnyxOne service are operated by ONYXONE TECHNOLOGIES LTD, a private limited company registered in England and Wales under company number 17352132, whose registered office is at 3 Mantua Street, London, England, SW11 2NE.

For procurement & partners

If you're evaluating OnyxOne, everything you need to begin diligence is public: a full, versioned legal suite, a documented security posture and named infrastructure sub-processors.

  • Complete legal set — Terms, Privacy, DPA, Acceptable Use, AML support statement, security and compliance — governed by England & Wales.
  • Named infrastructure sub-processors and a documented data-protection posture under UK GDPR.
  • A security page describing the controls actually in place, and a roadmap for SOC 2 / ISO 27001 (not yet held).

We won't confirm a customer, certification or capability we can't stand behind. For diligence, a DPA or a security review, contact us and we'll share the current entity details.

Talk to us

General, partnership and press enquiries: hello@onyxone.uk.