Transparency Center

Everything we claim, documented

Policies, disclosures, security and system status — published and versioned. Where a regulated capability isn't live yet, we say so.

System status ↗Non-custodialCompliance-ready

Security posture

Non-custodial by design

You connect your own wallet. We never hold your private keys, and we can't move your assets — the platform reads the chain, it doesn't hold your funds.

Server-only key handling

Sensitive keys and service credentials live and stay on the server. The browser only ever receives a public key, so a compromised client can't leak a secret.

Signed, single-use sign-in

Wallet sign-in issues a one-time nonce that is consumed on use and bound to this domain, defeating replay. Sessions are HMAC-signed, httpOnly and tamper-evident.

Encrypted in transit and at rest

Traffic is encrypted in transit and data at rest. Hardened HTTP security headers — HSTS, frame-ancestors none, nosniff and strict referrer/permissions policies — guard every request.

Audited smart contracts

Contracts powering drops and memberships are designed to be audited before deployment. Reports will be published in the Trust Center once contracts are audited.

Transparent on-chain

Every collectible, transfer and benefit is recorded on a public ledger you can independently verify — no need to take our word for what you own.

Compliance-ready

KYC/AML checks, geographic eligibility and sanctions screening are built into the account layer for regulated markets.

Truthful by policy

No invented volume, no fake scarcity, no guaranteed returns. Benefits are always explicitly defined.

Documented & disclosed

Terms, risk disclosures and asset descriptions are published and versioned in the Trust Center.

How OnyxOne is builtSchematic
Your browser + walletOnly ever receives the public anon key — never a secretVercel — edge delivery & hostingHTTPS/HSTS, cached SSR, hardened security headersApplication layer — server components & API routesServer-only secrets · SIWE verify · signed sessions · fail-safe adaptersSupabaseDatabase · auth · storagePublic blockchainsRead-only ownershipCard partnerPlanned · not yet engaged

A high-level view of the stack. Your browser only ever receives a public key; secrets and sign-in verification run server-side. The card partner is shown dashed because it is planned, not engaged.

Data handling & sub-processors

We collect the minimum needed to run a compliant, non-custodial platform and process personal data under the UK GDPR and the Data Protection Act 2018, supervised by the Information Commissioner's Office (ICO). These are the real infrastructure providers the platform is built on — Reap is listed as a planned card partner and is not yet engaged.

  • Vercel Inc.

    application hosting & edge delivery (US/EU regions)

  • Supabase

    database, authentication & storage (EU region)

  • Reap

    card issuing / BIN-sponsor partner (planned; not yet engaged)

For enterprise & partners

Documented & versioned

A complete legal suite — Terms, Privacy, DPA, AML & sanctions, risk and crypto disclosures — governed by the laws of England & Wales, published and dated in the Trust Center.

Compliance-ready foundation

KYC/AML, sanctions and PEP screening and geographic eligibility are built into the account layer, so regulated products can be gated correctly market by market.

Honest by policy

No fabricated volume, holders, endorsements or partnerships. Regulated capabilities launch through licensed partners, and anything not yet live is labelled as such.

SOC 2 and ISO 27001 are on our roadmap and are not yet held; we will publish attestations here once complete rather than claim them in advance. For diligence, KYB or a DPA, contact us and we'll share the current contracting-entity details.