Onky.ai · Security & compliance summary
Nothing you share ever reaches an AI lab.
Onky runs open-source models on EU infrastructure it controls, governed by default: default-deny policy enforcement, an OS-level audit trail, and human oversight on every action. This page is the one-page version of onky.ai for security and privacy reviews.
Last updated: 6 July 2026 · Print this page for a PDF copy
Regulatory posture
DPA at pilot signing: Onky acts as your data processor from day one
TodayUK & EU GDPR: consent-based capture, EU residency, deletion on request
TodayEU AI Act: built around its obligations
TodayOnky.ai Ltd: registered in the UK, Companies House 16490131
TodayISO 27001: certification in progress
In progressSOC 2 Type II: audit in progress
In progress
Infrastructure
- Hosted in the EU: europe-west1
- Data isolated: kept in region
- Retention you control: deletion on request
- No model training: on your data
- Open-source models: nothing sent to AI labs
Deployment
Managed EU cloud and open-weight models today. Private VPC next. On-premise and air-gapped deployments on request: the brain runs on open-source model families, which is what lets it run where proprietary-API models cannot.
Contacts & documents
Security questionnaires, our DPA, and vulnerability reports: security@onky.ai. Legal notices: privacy, cookies, subprocessors. Onky.ai Ltd is registered in England and Wales, Companies House 16490131.