Transparency Center

Everything we claim, documented

Policies, security, data-processing terms and system status — published and versioned. Where something isn't in place yet, we say so.

System status ↗Enterprise-readyUK GDPR

Security posture

Encrypted in transit and at rest

Customer records, evidence and case data are encrypted in transit and at rest. Hardened HTTP security headers — HSTS, frame-ancestors none, nosniff and strict referrer and permissions policies — guard every request.

Server-only secret handling

Sensitive credentials and service keys live and stay on the server. The browser never receives a secret, so a compromised client cannot leak one.

Role-based access & segregation of duties

Granular roles govern who can screen, investigate, approve and report. Segregation-of-duties controls ensure the same person cannot both raise and sign off a decision where your policy forbids it.

Immutable audit trail

Every action, decision, override and policy change is written to an append-only audit record — the evidence base you need for internal review, external audit and regulatory scrutiny.

Data residency & retention

Data location and retention are configurable to your regulatory obligations, and records are kept only as long as the law and your policy require, then deleted or anonymised.

Monitored and logged

Access, activity and integrations are logged and monitored, with a documented incident-response process. Capabilities that are not configured refuse safely rather than fail open.

Enterprise-ready

SSO, granular roles, data residency options and audit-grade logging designed for financial institutions and regulated enterprises.

A technology vendor, honestly framed

OnyxOne provides software; it is not a regulated financial institution and is not itself an obliged entity. Your firm remains responsible for its regulatory obligations.

Documented & disclosed

Terms, security controls, data-processing terms and sub-processors are published and versioned in the Trust Center.

How OnyxOne is builtSchematic
Your browserOnly ever receives the public anon key — never a secretVercel — edge delivery & hostingHTTPS/HSTS, cached SSR, hardened security headersApplication layer — server components & servicesServer-only secrets · role-based access · signed sessions · fail-safe integrationsSupabaseDatabase · auth · storageScreening & data providersConfigured per deploymentYour systems of recordIntegrated per deployment

A high-level view of the stack. Your browser only ever receives a public key; secrets and services run server-side. Screening and data providers are configured per deployment.

Data handling & sub-processors

We collect the minimum needed to run the platform and process personal data under the UK GDPR and the Data Protection Act 2018, supervised by the Information Commissioner's Office (ICO). These are the infrastructure providers the platform is built on; screening and data providers are contracted and configured per deployment.

  • Vercel Inc.

    application hosting & edge delivery (US/EU regions)

  • Supabase

    database, authentication & storage (EU region)

  • Google Ireland Limited

    website analytics (Google Analytics 4)

  • Screening & data providers

    contracted and configured per customer deployment

For enterprise & partners

Documented & versioned

A complete legal suite — Terms, Privacy, DPA, Acceptable Use, AML support statement, security and compliance — governed by the laws of England & Wales, published and dated in the Trust Center.

Built for regulated procurement

Everything a compliance, security or vendor-risk team needs for diligence is public: a documented security posture, named infrastructure sub-processors and a UK GDPR data-protection stance.

Honest by policy

No fabricated customers, metrics, certifications or partnerships. OnyxOne is a technology vendor, not a regulated firm, and anything not yet in place — including SOC 2 and ISO 27001 — is labelled as roadmap.

SOC 2 and ISO 27001 are on our roadmap and are not yet held; we will publish attestations here once complete rather than claim them in advance. For diligence, KYB or a DPA, contact us and we'll share the current contracting-entity details.