Data minimization
Select the sources and fields needed for the intended outcome. A spend baseline, routing evaluation, and collaborative workspace have different data requirements. Where supported, administrators can configure included and excluded sources, passthrough behavior, redaction, retention, and approved-user scope.Credentials
Provider, integration, and service credentials should be scoped to the minimum permissions required. Relay provider keys are treated as secrets and should not be exposed through normal read paths. Credential behavior, storage boundaries, and rotation procedures must be reviewed for the specific integration and deployment.Content and context
Visibility uses conversation content to understand workflows and provide meaningful organizational context. Relay and Sidekick also process content when routing, evaluating, or executing a request. The deployment model determines where that data plane runs. Customers can use Oximy Cloud, deploy in a customer VPC, or keep the data plane in their cloud while using the Oximy Cloud control plane.Policy and audit
Oximy connects approval, policy, access review, and audit workflows across the shared platform. Each product applies those controls to its own activity and administrative actions. Audit requirements should cover both observed AI activity and administrative actions such as access changes, policy updates, integration configuration, and routing changes.Questions to document
- Which systems send data to Oximy?
- Which fields and content are included?
- Where are data and credentials processed and stored?
- Who can access raw activity and administrative controls?
- How are retention, deletion, export, and incident response handled?
- Which commitments are product behavior, operational practice, or contractual terms?