Everything we claim, documented
Policies, security, data-processing terms and system status — published and versioned. Where something isn't in place yet, we say so.
Policies & disclosures
Terms of Service
The agreement between your organisation and OnyxOne
Privacy Policy
What we collect, why, and your control over it
Data Processing Agreement
For customers whose data we process on their behalf
Acceptable Use Policy
The line between good-faith use and abuse
Cookie Policy
What we store on your device, and what we measure without storing anything
AML & Sanctions Support
How OnyxOne helps customers meet their obligations
Compliance
How we think about our role
Security
Built like critical infrastructure
Accessibility Statement
An experience everyone can use
Responsible Disclosure
Report a vulnerability, responsibly
Security posture
Encrypted in transit and at rest
Customer records, evidence and case data are encrypted in transit and at rest. Hardened HTTP security headers — HSTS, frame-ancestors none, nosniff and strict referrer and permissions policies — guard every request.
Server-only secret handling
Sensitive credentials and service keys live and stay on the server. The browser never receives a secret, so a compromised client cannot leak one.
Role-based access & segregation of duties
Granular roles govern who can screen, investigate, approve and report. Segregation-of-duties controls ensure the same person cannot both raise and sign off a decision where your policy forbids it.
Immutable audit trail
Every action, decision, override and policy change is written to an append-only audit record — the evidence base you need for internal review, external audit and regulatory scrutiny.
Data residency & retention
Data location and retention are configurable to your regulatory obligations, and records are kept only as long as the law and your policy require, then deleted or anonymised.
Monitored and logged
Access, activity and integrations are logged and monitored, with a documented incident-response process. Capabilities that are not configured refuse safely rather than fail open.
Enterprise-ready
SSO, granular roles, data residency options and audit-grade logging designed for financial institutions and regulated enterprises.
A technology vendor, honestly framed
OnyxOne provides software; it is not a regulated financial institution and is not itself an obliged entity. Your firm remains responsible for its regulatory obligations.
Documented & disclosed
Terms, security controls, data-processing terms and sub-processors are published and versioned in the Trust Center.
A high-level view of the stack. Your browser only ever receives a public key; secrets and services run server-side. Screening and data providers are configured per deployment.
Data handling & sub-processors
We collect the minimum needed to run the platform and process personal data under the UK GDPR and the Data Protection Act 2018, supervised by the Information Commissioner's Office (ICO). These are the infrastructure providers the platform is built on; screening and data providers are contracted and configured per deployment.
- Vercel Inc.
application hosting & edge delivery (US/EU regions)
- Supabase
database, authentication & storage (EU region)
- Google Ireland Limited
website analytics (Google Analytics 4)
- Screening & data providers
contracted and configured per customer deployment
For enterprise & partners
Documented & versioned
A complete legal suite — Terms, Privacy, DPA, Acceptable Use, AML support statement, security and compliance — governed by the laws of England & Wales, published and dated in the Trust Center.
Built for regulated procurement
Everything a compliance, security or vendor-risk team needs for diligence is public: a documented security posture, named infrastructure sub-processors and a UK GDPR data-protection stance.
Honest by policy
No fabricated customers, metrics, certifications or partnerships. OnyxOne is a technology vendor, not a regulated firm, and anything not yet in place — including SOC 2 and ISO 27001 — is labelled as roadmap.
SOC 2 and ISO 27001 are on our roadmap and are not yet held; we will publish attestations here once complete rather than claim them in advance. For diligence, KYB or a DPA, contact us and we'll share the current contracting-entity details.