AI governance
that runs
on the device.

Oximy runs on Windows and Mac. It checks AI requests, files and agent actions before they go through, then warns, redacts or blocks according to your company’s AI security rules.

This includes bank details

Your policy keeps bank details out of AI. I can remove that column.

AI App
Customer-revenue.xlsx
CustomerRevenueBank account
$42,400•••• 4186
$18,850•••• 7092
$31,120•••• 2230
$12,960•••• 5518
$27,300•••• 0934
Summarise this month’s revenue.

50,000+

Devices monitored AI activity across the fleet

6,000+

AI tools tracked Visibility across the AI tools people use

500+

Policy combinations To block activity that crosses your rules

understands the request.
Your policy decides what happens.

Oxi-1, our own model, reads the content and context behind each AI request and agent action on the device. Oximy adds deterministic checks, and your company’s AI policy decides the outcome.

The policy engine

What would you like AI to stop doing?

Describe your AI governance policy in plain language. Set what employees and agents can do with AI tools, data and actions, then choose what happens when they cross the line.

Data protection

Keep private details
out of the next request.

Use AI data security rules to check prompts, images, spreadsheets and documents before they reach a supported AI tool.

This message has contact details

Send it without the phone number and email.

Remove and send
AI App

How can I help today?

Write a friendly reply to Priya Shah (+44 7700 900123, priya.shah@northline.co) confirming her refund for order 4417.

This image shows a passport

Identity documents stay out of AI tools.

Remove image
AI Browser
ai-assistant.example
passport-scan.jpg
PASSPORTP<GBRSHAH<<PRIYA<<<<<<<<<<<<
Fill in the travel form from this

Salaries stay in HR

Share team headcount, not individual pay.

Use team totals
Payroll-Q3.xlsx
NameTeamSalary
A. MorenoEngineering$148,000
J. ChenSales$96,500
R. PatelOperations$88,200
L. OkaforEngineering$132,750
S. KimDesign$104,300

This document has health details

Send it without the diagnosis and medication.

Redact and send
AI App
Intake-notes.pdf2 pages

Patient intake notes

Diagnosis: type 2 diabetes

Medication: metformin 500 mg

Next appointment in six weeks.

Summarise these notes for the team

Coding-agent safety

Stop an agent from
deleting production data.

Choose which files, commands and systems a coding agent can use. Oximy checks each action against your AI agent security rules before it runs.

Watching this agent

No issues yet
Clean up the test records.

Proposed action

Destructive actions

Stop deletion of production customer records.

Business controls

Limit the runs. Approve the spend.

Bring AI spend management into your policies. Set run limits, require approval above a budget, and decide which business actions an agent can take.

  • Routine limits

    Set a maximum number of concurrent runs per person.

  • Usage budgets

    Ask before an action exceeds a sample team budget.

  • Purchase approvals

    Review the amount before a subscription is bought.

Mac

It stays on the device.
It shows up when needed.

Oximy brings AI runtime security to supported desktop apps, browser tools and coding agents on Windows and Mac. Checks run locally, and when a rule applies, the employee sees what they can do next.

Desktop AI appsRequests & files
Browser AI toolsAccounts & uploads
Coding agentsCommands & actions

Local device

Oximy policy engine

Deterministic checks + Oxi-1

Click an outcome

Pick an outcome to see what the employee experiences.

The difference

Your policy, applied
before the action.

Oximy enforces AI policy inside the work. It checks files, requests and actions while there is still time to allow, warn, redact, ask for review or block.

When this happensWithout OximyWITH OXIMY
A customer spreadsheet goes into AIThe employee has to spot and remove private details themselves.Bank details are caught in the upload. The employee gets a way to continue without them.
An agent proposes a destructive commandSomeone has to notice which system the command will affect.The production target is checked against the policy. The prohibited command is stopped before it runs.
An automation crosses a business limitThe team has to check usage and spending against a separate set of rules.Your limit becomes a check at the action. A run can wait, or a purchase can require approval.
An employee needs to know what to do nextA policy document leaves them to interpret the rule in the moment.A small notification explains the issue and the next permitted step, inside the work they are already doing.

Backed by Y Combinator
Advised by security and technology leaders.

Investors

  • Gokul RajaramProduct leader; board experience at Pinterest and Coinbase

Advisors

  • Patti Degnan

    Patti Degnan

    Former CISO

    Notion

  • Adam Messinger

    Adam Messinger

    Former CTO

    Twitter

  • Greg Morrison

    Greg Morrison

    Former CIO

    Enterprises

  • Mark Sunday

    Mark Sunday

    Former CIO

    Oracle

What technology leaders tell us.

They’re tackling problems I know from leading technology at a large enterprise: how technology is used, what value it creates and how to govern it. If I were a CIO today, Oximy would have my attention.
Former Chief Information OfficerGlobal Enterprise Software Company with 100K+ Employees
We’ve been fine-tuning the product with Oximy using real data from our environment. Internally, the right people already know Oximy by name. When a reporting need comes up, they ask, ‘Can Oximy do this?’
Senior IT ExecutiveGlobal Software Company with $1B+ in Reported Annual Revenue
We’d been looking for a way to see which AI tools people were using, including outside our company accounts. Oximy’s endpoint agent addresses a visibility gap we’d already been trying to solve.
System AdministratorB2B Software Company with 51–200 Employees
I’ve been championing the product internally and taking it to our legal team, because I see potential our existing tools don’t address. If Oximy delivers, it could become very hard for companies to walk away from.
Senior Director, Enterprise ArchitectureGlobal Software Company with $1B+ in Reported Annual Revenue
I know firsthand how hard it is to connect engineering investment to the work people do, and AI adds another layer. Oximy’s focus on visibility makes sense to me.
Former Chief Technology OfficerGlobal Technology Company with $2B+ Annual Revenue During His Tenure
Understanding AI usage and cost is a useful place to start, and I see a path into the governance capabilities companies will need as they adopt more AI. I’m excited to try it out.
Co-Founder & Chief Technology OfficerDeveloper Software Company with 200+ Employees
Too much of our picture of AI use comes from anecdotes and self-reporting. What stood out about Oximy is the visibility into the tools people use and the nature of that use.
Co-Founder & Chief Executive OfficerDigital Learning and Technology Company with 500+ Employees
CIOs are being asked to explain their AI investments to CEOs and boards, and that’s hard to delegate. Oximy is focused on a real issue for those leaders.
Former Chief Information OfficerDiversified Global Enterprise with 30K+ Employees
I see a promising way to bring the visibility enterprises expect around software usage and spend into AI. That’s highly relevant to the large customers we work with.
Chief Executive OfficerGlobal Technology Consultancy with 800+ Team Members
Enterprises need a much clearer understanding of AI usage, spend and governance as the number of tools grows. Oximy looks like a solution to a need I expect to keep growing.
Investment AssociateSoftware Investment Firm with 11–50 Employees and $2B in Assets Under Management

FAQs

Before you put it
on your devices.

Oxi-1 is Oximy's proprietary remediation foundation model. It runs locally, on demand, to interpret content and context for security and business policies. It works with the policy engine's deterministic checks for limits, permissions and required approvals.

No. Employees keep working in their existing tools. When a policy needs their attention, Oximy shows a small notification explaining the issue and the permitted next step. The outcome depends on your rule: a warning, redaction, approval request or block.

Yes. Oximy's policy engine and local AI model run on Windows and Mac devices. Policies can cover desktop AI apps, browser AI activity and coding agents; the specific checks available depend on the application and action.

Oximy's content inspection and policy evaluation run locally. A request your policy allows can still be sent to the AI provider you chose. Local inspection and an AI tool's own data handling are separate.

What should AI be allowed
to do in your business?

Bring a security rule, an agent boundary or a usage limit. See how it becomes a policy on your Macs.