Our mission
Compliance teams are asked to do more, with more scrutiny, on tooling that is fragmented across point solutions, spreadsheets and shared inboxes. The result is work that is hard to see, harder to audit, and slow to defend.
OnyxOne exists to make compliance operations feel as considered and dependable as the best enterprise software: one platform, one record, one workflow — with a defensible audit trail behind every decision.
The problem we're solving
Governance, risk and compliance has become one of the most consequential functions in a regulated business, and one of the worst-served by its tooling. A single programme is typically spread across a screening tool, a case tracker, a risk register in a spreadsheet, a policy library in a document store and an audit file assembled by hand. Data is copied between them, context is lost at every hop, and no single record shows the full history of a customer, a control or a decision.
The cost is not only inefficiency. When work lives in disconnected systems, evidence has to be reconstructed after the fact, oversight depends on whoever remembers where things are, and the answer to "how was this decided?" is a scramble rather than a record. That is precisely the question a regulator, an auditor or a board asks — and precisely where fragmented tooling fails.
One system of record
OnyxOne is built on a single premise: a governance, risk and compliance programme should run on one system of record, not a patchwork of point tools. Risk, controls, policy, obligations, audit, evidence, cases and reporting write to the same underlying record, so a decision, the evidence behind it and its place in the wider programme are never separated.
That is what turns compliance from a set of disconnected activities into an operating system — where every action feeds the next, oversight is continuous rather than periodic, and the audit trail is a by-product of doing the work rather than a project in its own right.
What we're building
A single, coherent platform where risk, controls, policies, obligations, audit, evidence, compliance cases and regulatory reporting operate together instead of in isolation.
- Screening & due diligence
- Sanctions, PEP and adverse-media screening wrapped in structured CDD, KYC, KYB and EDD workflows, mapped to your own risk policy.
- Cases & investigations
- Alerts routed into cases with evidence, entity links and recorded decisions — a defensible trail from alert to closure.
- Governance, reporting & audit
- Policy and controls, regulatory reporting, and an immutable audit trail so the whole programme is visible and defensible.
Where we sit
OnyxOne is the layer between your teams and your systems and data sources. Your teams work in one place; the platform centralises screening, cases and risk and connects to the systems of record and data providers your deployment requires.
One platform for the whole compliance programme, connected to the systems and data sources your deployment requires.
How we build
- Truthful by policy — no fabricated customers, metrics, certifications, endorsements or guarantees.
- A vendor, honestly framed — OnyxOne is technology, not a regulated firm; your obligations remain yours.
- Configurable, not prescriptive — the platform enforces your policy and risk model, not ours.
- Honest empty states — where something isn't in place yet, we say so plainly rather than dress it up.
- Built like critical infrastructure — server-only secrets, role-based access and audit-grade logging from day one.
The platform, honestly
OnyxOne runs on a deliberately conventional, dependable stack rather than anything exotic. The application is hosted and delivered on Vercel; data, authentication and storage run on Supabase; screening and data providers are configured per deployment. Sensitive keys stay on the server and never reach your browser.
A high-level view. Your browser only ever receives a public key; secrets and services run server-side.
Our legal entity
This website and the OnyxOne service are operated by ONYXONE TECHNOLOGIES LTD, a private limited company registered in England and Wales under company number 17352132, whose registered office is at 3 Mantua Street, London, England, SW11 2NE.
For procurement & partners
If you're evaluating OnyxOne, everything you need to begin diligence is public: a full, versioned legal suite, a documented security posture and named infrastructure sub-processors.
- Complete legal set — Terms, Privacy, DPA, Acceptable Use, AML support statement, security and compliance — governed by England & Wales.
- Named infrastructure sub-processors and a documented data-protection posture under UK GDPR.
- A security page describing the controls actually in place, and a roadmap for SOC 2 / ISO 27001 (not yet held).
We won't confirm a customer, certification or capability we can't stand behind. For diligence, a DPA or a security review, contact us and we'll share the current entity details.
Talk to us
General, partnership and press enquiries: hello@onyxone.uk.