Welcome to Onyx's Trust Center. Our commitment to data privacy and security is embedded in every part of our business. Use this Trust Center to learn about our security posture and request access to our security documentation.

Controls
Product Security
Security capabilities in the Onyx platform that customers use to control access and monitor activity.
Onyx systems that handle sensitive information, accept network connections, or manage access control record audit logs capturing what activity was performed, who performed it, when and how, and the result. Logged events include user authentication, all actions taken by administrators, and attempts to grant, modify, or revoke access rights.
Multi-factor authentication is required on every system that offers it. Access to Onyx systems and applications is controlled through unique user login IDs, with authentication requirements enforced consistently across all systems.
All access to Onyx systems and data is regulated through role-based access control, with the level of access based on the minimum necessary to carry out a user's job responsibilities. Segregation of duties is considered when user rights are assigned.
Data Security
How Onyx classifies, encrypts, backs up, and physically protects the data it holds.
Data is classified at the time of creation or acquisition into one of three levels: Confidential/Restricted, Internal Use, or Public. The classification determines the baseline security controls, handling requirements, and retention that apply to that data.
Complete backups are performed daily and automatically replicated to a separate region within the same country. Backups are encrypted in the same way as live production data, and backup failures trigger an incident alert to the Security Officer.
Data encryption keys use AES-256 with 256-bit key sizes, as defined in Onyx's Encryption Policy. Backups are encrypted to the same standard as live production data.
Traffic to the Onyx platform is protected in transit using SSL/TLS certificates. Cryptographic controls follow the approved algorithms and key sizes defined in Onyx's Encryption Policy, and conform to international standards.
Physical access to Onyx facilities is restricted using badge readers and smart locks that track all access, and on-site visitors must be escorted by an employee at all times. A record is retained for each physical access to production environments and secure facilities for a minimum of seven years.
App Security
Practices that keep the Onyx platform secure through development, testing, and vulnerability remediation.
Onyx operates a coordinated vulnerability disclosure program and accepts reports from external security researchers at security@onyx.security. Onyx commits not to pursue legal action against researchers who test in good faith within the published scope and who withhold public disclosure until a mutually agreed timeframe.
Onyx follows a consistent and repeatable software development lifecycle that maintains information security at every stage. Security requirements are identified through risk assessment during the requirements phase, and each software unit is tested for security vulnerabilities before release.
Product systems are scanned for vulnerabilities on a recurring basis using a combination of open-source and commercial vulnerability testing tools. Every finding is logged, assigned a priority, and tracked to resolution against defined remediation SLAs, with records retained for at least three years.
Legal
Contractual and insurance commitments Onyx makes to its customers.
Onyx publishes the full list of third parties that may process customer data, including each subprocessor's purpose and location. See the Subprocessors tab.
Onyx maintains a cyber insurance plan that provides coverage for security incidents.
Onyx's Data Processing Addendum is Exhibit B of the Master Services Agreement.
Onyx's Master Services Agreement is published at onyx.security/msa.
Onyx's Service-Level Agreement is Exhibit A of the Master Services Agreement.
Onyx's privacy policy describes how personal data is collected, used, and protected. Read it at onyx.security/privacy-policy.
The terms governing use of the Onyx platform are published at onyx.security/terms-of-use.
Onyx's completed IRS Form W-9 is available on request for vendor onboarding and payment setup. Request it from the Documents tab under Insurance and finance forms.
Access Control
How access to Onyx systems and data is requested, authenticated, reviewed, and logged.
All access to audit logs is itself logged, along with the initialization of new audit logs and any starting, stopping, or pausing of existing ones. Each log record identifies the action taken, the subsystem that performed it, and identifiers for the user requesting it.
Access to systems and data is granted on a minimum necessary basis for a user's job responsibilities, and every access request requires formal documentation and authorization. User accounts, including third party and vendor accounts, are reviewed by management on a half-year basis to confirm they remain appropriate.
Access is assigned under the principle of least privilege, limited to the minimum amount of data access required for a user's job classification. Any access beyond that minimum requires a documented justification as part of the access request and explicit approval.
System activity is logged and monitored across applications, infrastructure including cloud infrastructure, network, and security tooling. Logged activity includes authentication events, all invalid logical access attempts, configuration changes, and detection of suspicious or malicious activity.
Passwords must be at least 12 characters, are never displayed or transmitted in plain text, and are stored with a unique salt as a one-way hash using an approved hashing algorithm. Passwords are treated as confidential, are shared only through an approved password manager or single sign-on, and are rotated immediately if compromise is suspected.
Infrastructure
We take great care to work with best-in-class infrastructure providers that provide secure computing and storage. We are happy to provide more details about our infrastructure upon request.
Endpoint Security
We follow industry best practices for endpoint security. We are happy to provide more details about our endpoint security practices upon request.
Network Security
We protect our corporate network against external & internal threats.
Corporate Security
Company-wide security operations covering assets, incident response, and independent testing.
Onyx maintains an inventory of all physical and virtual assets under its management, recording each asset's owner, purpose, and classification. Assets are tracked through their full lifecycle from acquisition to disposal, and company-owned devices are subject to a complete data wipe when required.
Onyx maintains a documented incident response plan covering detection, containment, investigation, resolution, and communication to employees, customers, and partners. All users are required to report suspected vulnerabilities or incidents, and confirmed incidents are investigated within timelines set by severity.
Penetration testing is performed regularly by either a certified penetration tester on Onyx's security team or an independent third party. Findings are analyzed by the Security Officer together with engineering and tracked to remediation.
BC/DR
Onyx's plans for maintaining and restoring service after a disruption or disaster.
Onyx maintains a documented business continuity plan covering the backup and recovery of systems and data following a disruption. The plan is simulated and tested at least once a year, with metrics measured and recovery improvements filed.
All business data is stored or replicated into a company controlled repository and backed up daily to a separate region. Backups are encrypted, monitored, and alerted on, with retention periods set by data classification and applicable regulatory and contractual requirements.
Onyx's disaster recovery plan defines notification and activation, recovery, and reconstitution phases for restoring operations after a disaster. Systems are categorized as critical or non-critical, with critical systems restored first.
Training
Security and privacy training required of everyone who works at Onyx.
Onyx Security provides ongoing security and privacy training to all employees and maintains records of completion to ensure staff handle information assets responsibly.
Onyx Security conducts phishing training as part of security awareness training to help employees recognize and respond to phishing threats.
Onyx Security’s security awareness program requires all new hires to complete security and privacy training at onboarding and conducts annual refresher courses and policy acknowledgments for employees, contractors, and third-party users, with role-based briefings on information security responsibilities prior to access. Training covers security and privacy requirements, correct use of information assets and facilities, safe use of assets, privacy obligations, and current threat scenarios through interactive web-based modules, in-person sessions, newsletters, and periodic phishing simulations. Completion and acknowledgment records are tracked and the program undergoes annual review and approval by the security team.
Continuous Monitoring
We continuously monitor our systems for security threats and vulnerabilities. We are happy to provide more details about our continuous monitoring practices upon request.




