One platform, not a stack of point tools
Most compliance operations are assembled from separate products — one for screening, another for cases, a spreadsheet for risk, a document store for policy — held together by manual work. Every integration is a seam where data is copied, context is lost and cost accumulates.
OnyxOne replaces that stack with a single operating system. Risk, controls, policy, obligations, audit, evidence, cases and reporting share one record and one workflow, so the whole programme is visible in one place instead of scattered across tools that were never designed to work together.
Your teams work in one place; the platform centralises screening, cases and risk and connects to the systems and data sources your deployment requires.
Audit-ready by design
Audit readiness is not a report you generate at the end; it is a property of how the work is captured as it happens. Every screening result, risk decision, case disposition, override and policy change is written to an immutable, timestamped, attributed audit trail as you work.
When a regulator, an internal auditor or the board asks how a decision was made, the answer already exists on the record — it does not have to be reconstructed from memory, email and screenshots after the fact.
An append-only record of every action and decision — ready for internal review, external audit and regulators.
Configured to your frameworks, not ours
A GRC platform that imposes its own model is a platform you fight. OnyxOne is configured to your policy, your risk-rating methodology, your control library and the frameworks and regulations your markets require — thresholds, workflows, roles and approvals all reflect your programme.
Screening and data providers are contracted and configured per deployment rather than fixed to a single named source, so the platform enforces the programme you have designed instead of forcing you to redesign it around the tool.
Enterprise security and governance
- Server-only secret handling — the browser never receives a secret; sensitive keys and service credentials stay on the server.
- Role-based access with segregation of duties, so the same person cannot both raise and sign off a decision where your policy forbids it.
- Encryption in transit and at rest, signed and tamper-evident sessions, and hardened HTTP security headers on every request.
- Fail-safe integrations — capabilities that are not configured refuse rather than fail open, and errors never leak internal detail.
- Configurable data residency and retention, and an immutable audit trail across the whole platform.
We build to recognised security standards. SOC 2 and ISO 27001 are on our roadmap and are not yet held — we will publish attestations once they are complete rather than claim them in advance.
Assistive AI that keeps humans in control
Where OnyxOne applies AI, it is to assist the people accountable for a decision — summarising evidence, surfacing what matters and reducing noise — never to make regulatory decisions on their behalf. A human remains in control of every consequential outcome, and the reasoning is recorded on the audit trail.
That is a deliberate posture. In a regulated programme, accountability cannot be delegated to a model, and we do not design as though it can.
A vendor you can put through diligence
Everything a compliance, security or vendor-risk team needs to begin diligence is public: a complete, versioned legal suite, a documented security posture and named infrastructure sub-processors — all governed by the laws of England & Wales.
- Full legal set — Terms, Privacy, DPA, Acceptable Use, AML support statement, security and compliance.
- A documented data-protection stance under the UK GDPR and Data Protection Act 2018.
- Honest scoping — OnyxOne is a technology vendor, not a regulated firm or an obliged entity; your obligations remain yours.
Talk to us about your evaluation
For a demo, a security review, a DPA or a procurement conversation, email hello@onyxone.uk with your organisation and what you need to assess.