Everything we claim, documented
Policies, disclosures, security and system status — published and versioned. Where a regulated capability isn't live yet, we say so.
Policies & disclosures
Terms of Service
The agreement between you and OnyxOne
Privacy Policy
What we collect, why, and your control over it
Data Processing Agreement
For business customers whose users we process on their behalf
Acceptable Use Policy
The line between good-faith use and abuse
Risk Disclosure
Digital assets carry real risk — read this
Crypto Asset Disclaimer
How crypto funding and conversion work here
Cookie Policy
We default to the privacy-preserving choice
AML & Sanctions Policy
Financial crime has no place here
Compliance
How we think about regulation
Security
Built like financial infrastructure
Accessibility Statement
An experience everyone can use
Bug Bounty
Report a vulnerability, responsibly
Security posture
Non-custodial by design
You connect your own wallet. We never hold your private keys, and we can't move your assets — the platform reads the chain, it doesn't hold your funds.
Server-only key handling
Sensitive keys and service credentials live and stay on the server. The browser only ever receives a public key, so a compromised client can't leak a secret.
Signed, single-use sign-in
Wallet sign-in issues a one-time nonce that is consumed on use and bound to this domain, defeating replay. Sessions are HMAC-signed, httpOnly and tamper-evident.
Encrypted in transit and at rest
Traffic is encrypted in transit and data at rest. Hardened HTTP security headers — HSTS, frame-ancestors none, nosniff and strict referrer/permissions policies — guard every request.
Audited smart contracts
Contracts powering drops and memberships are designed to be audited before deployment. Reports will be published in the Trust Center once contracts are audited.
Transparent on-chain
Every collectible, transfer and benefit is recorded on a public ledger you can independently verify — no need to take our word for what you own.
Compliance-ready
KYC/AML checks, geographic eligibility and sanctions screening are built into the account layer for regulated markets.
Truthful by policy
No invented volume, no fake scarcity, no guaranteed returns. Benefits are always explicitly defined.
Documented & disclosed
Terms, risk disclosures and asset descriptions are published and versioned in the Trust Center.
A high-level view of the stack. Your browser only ever receives a public key; secrets and sign-in verification run server-side. The card partner is shown dashed because it is planned, not engaged.
Data handling & sub-processors
We collect the minimum needed to run a compliant, non-custodial platform and process personal data under the UK GDPR and the Data Protection Act 2018, supervised by the Information Commissioner's Office (ICO). These are the real infrastructure providers the platform is built on — Reap is listed as a planned card partner and is not yet engaged.
- Vercel Inc.
application hosting & edge delivery (US/EU regions)
- Supabase
database, authentication & storage (EU region)
- Reap
card issuing / BIN-sponsor partner (planned; not yet engaged)
For enterprise & partners
Documented & versioned
A complete legal suite — Terms, Privacy, DPA, AML & sanctions, risk and crypto disclosures — governed by the laws of England & Wales, published and dated in the Trust Center.
Compliance-ready foundation
KYC/AML, sanctions and PEP screening and geographic eligibility are built into the account layer, so regulated products can be gated correctly market by market.
Honest by policy
No fabricated volume, holders, endorsements or partnerships. Regulated capabilities launch through licensed partners, and anything not yet live is labelled as such.
SOC 2 and ISO 27001 are on our roadmap and are not yet held; we will publish attestations here once complete rather than claim them in advance. For diligence, KYB or a DPA, contact us and we'll share the current contracting-entity details.