Platform layers
Data sources
Oximy can receive data from first-party integrations, organization-managed endpoints, browser extensions, local collectors, model traffic, and product APIs. Each source has a different coverage and privacy profile.Shared control plane
The platform connects workspace identity, organization structure, access, policy, integrations, billing, audit history, and product configuration. It provides consistent context without collapsing all product data into one undifferentiated surface.Product services
- Visibility attributes activity, usage, spend, adoption, and risk.
- Relay evaluates and applies model-routing decisions.
- Sidekick manages collaborative threads, artifacts, memory, tools, and execution.
Customer systems
Oximy connects to existing identity providers, model providers, gateways, SaaS tools, local environments, and cloud infrastructure. The architecture is designed to add control around these systems rather than require their replacement.The operating loop
This product loop operates today. Visibility establishes what is happening. Sidekick provides a governed place to perform work. Relay controls model selection underneath that work and other model traffic. Resulting activity returns to Visibility.Deployment models
- Oximy Cloud
- Customer VPC
- Hybrid
Oximy operates the control plane and data plane in Oximy Cloud. This is the simplest deployment when the customer does not require its data plane to run in its own environment.
The hosting model changes the infrastructure boundary, not the product model. Visibility, Sidekick, Relay, and the shared platform capabilities remain available across the supported deployments.
Independent adoption
Each product has a useful standalone architecture:- Visibility can observe activity without Relay or Sidekick.
- Relay can route traffic without Visibility or Sidekick.
- Sidekick can run with provider and harness choices selected by the customer.
Trust boundaries
The exact trust boundary depends on the selected deployment:- An integration grants scoped access to a provider or application.
- An endpoint or browser component observes only configured sources.
- Relay can observe traffic, return a routing decision, or proxy the request.
- Sidekick can execute through local or cloud environments with different credential boundaries.