Built for teams who operate
in demanding markets.
ONX is designed to meet the security and governance expectations of enterprise procurement, legal, and security teams — without compromising speed or commercial value.
Encryption at rest & in transit
GDPR-aligned architecture
EU AI Act: limited risk
Role-based access & RLS
Security Architecture
How data flows through the ONX platform — from customer browser to database, and out to external processors. Encryption boundaries and tenant isolation are highlighted.
ONX — Security Architecture Overview
Customer Browser
User / Sales Rep
HTTPS onlyVercel Edge
Global CDN · HSTS enforced
ONX App
Next.js · API Routes
Supabase Auth
JWT tokens · session management
PostgreSQL DB
AES-256 at rest
RLS enforcedAudit Trail
Append-only · immutable
TTL enforcedAnthropic
Company context only
No personal dataOpenAI
Supplementary flows
No personal dataPeople Data Labs
Firmographic data
Business data onlyPerplexity AI
Public web signals
Business data onlyInfrastructure
Encryption
Customer-managed encryption keys (CMEK) are available on Enterprise plans on request.
Access Controls
Data Governance & Privacy
AI Governance
EU AI Act — Preliminary Classification
Preliminary internal assessment indicates ONX currently operates outside EU AI Act high-risk classifications (Annex III). ONX provides commercial decision-support tools only — not employment, credit, law enforcement, or healthcare decisions.
Subprocessors
ONX uses a limited set of third-party subprocessors. Each is covered by a DPA and Standard Contractual Clauses (SCCs) where data is transferred outside the EEA. 30 days' notice is provided for new subprocessors.
Uptime & Reliability
Enterprise SLA documentation available on request.
Incident Response
To report a suspected incident: security@optimalnexus.com
Vulnerability Disclosure
Optimal Nexus Ltd operates a responsible disclosure policy. If you discover a security vulnerability in ONX, we ask that you report it privately before public disclosure so we can investigate and resolve it.
We are not currently operating a formal bug bounty programme. This is under review.
Compliance Roadmap
Current posture and planned milestones. We publish this because enterprise buyers deserve an honest picture, not a marketing badge.
Download the procurement pack
DPIA · LIA · AI Transparency · Subprocessors — generated live, always current.
Need documentation for procurement?
DPA, DPIA, subprocessor list, AI governance summary — available on request.