Onky.ai · Security & compliance summary

Nothing you share is used to train AI.

Onky runs open-weight models only, with no frontier AI lab in the loop, and the whole platform can run inside your own perimeter, governed by default: default-deny policy enforcement, an OS-level audit trail, and human oversight on every action. This page is the one-page version of onky.ai for security and privacy reviews.

Last updated: 11 August 2026 · Print this page for a PDF copy

Regulatory posture

  • DPA at pilot signing: Onky acts as your data processor from day one

    Today
  • UK & EU GDPR: consent-based capture, retention controls, deletion on request

    Today
  • EU AI Act: built around its obligations

    Today
  • Onky.ai Ltd: registered in the UK, Companies House 16490131

    Today
  • ISO 27001: certification in progress

    In progress
  • SOC 2 Type II: audit in progress

    In progress

Data handling

  • Open-source models: no frontier AI lab in the loop
  • No model training: on your data
  • Retention you control: deletion on request
  • No vendor lock-in: open weights, models you can swap
  • Runs where you need it: cloud, VPC, on-premise, air-gapped

Deployment

Managed cloud and open-weight models today. Private VPC next. On-premise and air-gapped deployments on request: the brain runs on open-source model families, which is what lets it run where proprietary-API models cannot.

Contacts & documents

Security questionnaires, our DPA, and vulnerability reports: security@onky.ai. Legal notices: privacy, cookies, subprocessors. Onky.ai Ltd is registered in England and Wales, Companies House 16490131.