Book a demo

Onky.ai · Security & compliance summary

Nothing you share ever reaches an AI lab.

Onky runs open-source models on EU infrastructure it controls, governed by default: default-deny policy enforcement, an OS-level audit trail, and human oversight on every action. This page is the one-page version of onky.ai for security and privacy reviews.

Last updated: 6 July 2026 · Print this page for a PDF copy

Regulatory posture

  • DPA at pilot signing: Onky acts as your data processor from day one

    Today
  • UK & EU GDPR: consent-based capture, EU residency, deletion on request

    Today
  • EU AI Act: built around its obligations

    Today
  • Onky.ai Ltd: registered in the UK, Companies House 16490131

    Today
  • ISO 27001: certification in progress

    In progress
  • SOC 2 Type II: audit in progress

    In progress

Infrastructure

  • Hosted in the EU: europe-west1
  • Data isolated: kept in region
  • Retention you control: deletion on request
  • No model training: on your data
  • Open-source models: nothing sent to AI labs

Deployment

Managed EU cloud and open-weight models today. Private VPC next. On-premise and air-gapped deployments on request: the brain runs on open-source model families, which is what lets it run where proprietary-API models cannot.

Contacts & documents

Security questionnaires, our DPA, and vulnerability reports: security@onky.ai. Legal notices: privacy, cookies, subprocessors. Onky.ai Ltd is registered in England and Wales, Companies House 16490131.