Built for teams who operate
in demanding markets.
ONX is designed to meet the security and governance expectations of enterprise procurement, legal, and security teams, without compromising speed or commercial value.
Encryption at rest & in transit
GDPR-aligned architecture
EU AI Act: controls built in
Role-based access & RLS
Security Architecture
How data flows through the ONX platform, from customer browser to database, and out to external processors. Encryption boundaries and tenant isolation are highlighted.
ONX, Security Architecture Overview
Customer Browser
User / Sales Rep
HTTPS onlyVercel Edge
Global CDN · HSTS enforced
ONX App
Next.js · API Routes
Supabase Auth
JWT tokens · session management
PostgreSQL DB
AES-256 at rest
RLS enforcedAudit Trail
Append-only · immutable
TTL enforcedAnthropic
Company context only
No personal dataOpenAI
Supplementary flows
No personal dataPeople Data Labs
Firmographic data
Business data onlyPerplexity AI
Public web signals
Business data onlyInfrastructure
Encryption
Customer-managed encryption keys (CMEK) are available on Enterprise plans on request.
Access Controls
Data Governance & Privacy
AI Governance
EU AI Act, Our Approach
Every AI feature in ONX is decision support with human review, per-decision logging and accuracy monitoring. Most features are commercial decision-support outside the Act's high-risk categories; where a feature touches Annex III territory, candidate–job match scoring in Hiring. It is operated under the Act's strictest control framework: mandatory human review before any score is used, stated reasoning alongside every score, per-decision audit logs and candidate notification. The assessment is reviewed annually and whenever processing materially changes.
Subprocessors
ONX uses a limited set of third-party subprocessors. Each is covered by a DPA and Standard Contractual Clauses (SCCs) where data is transferred outside the EEA. 30 days' notice is provided for new subprocessors.
Uptime & Reliability
Enterprise SLA documentation available on request.
Incident Response
To report a suspected incident: security@optimalnexus.com
Vulnerability Disclosure
Optimal Nexus Ltd operates a responsible disclosure policy. If you discover a security vulnerability in ONX, we ask that you report it privately before public disclosure so we can investigate and resolve it.
We are not currently operating a formal bug bounty programme. This is under review.
Compliance Roadmap
Current posture and planned milestones. We publish this because enterprise buyers deserve an honest picture, not a marketing badge.
Download the procurement pack
DPIA · LIA · AI Transparency · Subprocessors, generated live, always current.
Need documentation for procurement?
DPA, DPIA, subprocessor list, AI governance summary, available on request.