Principles
- Truthful by policy: no invented customers, metrics, certifications, partnerships or guarantees.
- Clear scope: OnyxOne is a technology vendor, not a regulated firm or an obliged entity.
- Configurable, not prescriptive: the platform enforces the customer's own policy and risk model.
- Documented and disclosed: terms, security and data-processing terms are published and versioned.
Certifications & roadmap
We build to recognised security standards. SOC 2 and ISO 27001 are on our roadmap and are not yet held; we will publish attestations here once they are complete rather than claim them in advance. Our legal suite is governed by the laws of England & Wales and our data-protection posture follows the UK GDPR and Data Protection Act 2018.
Availability
Availability and configuration are scoped per deployment, including data residency and the screening and data providers integrated for a given customer.