Enterprise-Grade Security

Your data is in safe hands

From encryption to access control, we enforce rigorous standards to keep your data secure, private, and compliant.

SOC 2 Type IHIPAA CompliantGDPR Compliant

Certified & Compliant

Certified and compliant with rigorous international standards

SOC 2 Type ICertified

SOC 2 Type I

Independently audited for security, availability, and confidentiality. Type II certification currently underway.

HIPAACompliant

HIPAA

Fully compliant with healthcare data protection requirements. BAAs available for enterprise customers.

GDPRCompliant

GDPR

Full compliance with EU data protection regulations. DPAs available upon request.

Enterprise-Grade Security

Built for security from day one

Your data is protected at every layer - from encryption to access control to audit logging.

Data Encryption

All data encrypted in transit (TLS 1.3) and at rest (AES-256). Your data is protected at every layer.

Flexible Hosting

Choose where your data lives: US-based, EU-based, or fully on-premises deployment to meet your compliance needs.

No Model Training

We contractually guarantee your data is never used to train AI models. Your inputs, outputs, and documents remain exclusively yours.

SSO & Access Control

Enterprise SSO support with SAML 2.0 and OIDC. Fine-grained role-based access control ensures the right people have the right access.

Comprehensive Audit Logs

Every action is logged and traceable. Full visibility into who accessed what, when, and from where for compliance reviews.

Annual Penetration Testing

We partner with top-tier security firms for annual penetration tests to proactively identify and mitigate risks.

Zero Trust Architecture

No user or system is inherently trusted. Access is always verified, limited, and logged following Zero Trust principles.

Data Retention Policies

Set and manage data retention periods aligned with your internal policies and regulatory requirements via our Trust Center.

AI Security Standards

Aligned with major AI security frameworks

Oximy helps you meet the requirements of leading AI security and governance frameworks. We continuously update our platform as standards evolve.

OWASP LLM Top 10

Protection against all 10 critical LLM vulnerabilities

NIST AI RMF

Aligned with the NIST AI Risk Management Framework

ISO 42001

AI management system standards alignment

MITRE ATLAS

Defense against adversarial AI attack techniques

AIUC-1

AI User Controls standard compliance

EU AI Act

Ready for European AI regulatory requirements

Continuous Compliance

Our platform evolves with the AI security landscape

6+

Frameworks

100%

Coverage

24/7

Monitoring

Security FAQs

All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption. For customers who require additional control, we offer options to encrypt data with their own encryption keys (BYOK). Your data is protected at every layer of our infrastructure.

We offer flexible hosting options to meet your compliance needs. Choose between US-based hosting, EU-based hosting, or on-premises deployment. Data never leaves your chosen region, and we can provide documentation for regulatory requirements.

No, never. We contractually guarantee through our Security Addendum that your data stays yours. We do not use your inputs, outputs, or uploaded documents to train or fine-tune any AI models. Your confidential data remains secure and private.

We support enterprise SSO with SAML 2.0 and OIDC protocols, giving you full control over user authentication. Our role-based access control (RBAC) ensures users only have access to what they need. All access is logged and auditable.

We partner with top-tier security firms for annual penetration tests covering the full platform scope. We follow an 'assume breach' methodology to proactively identify and mitigate risks. Our SOC 2 Type I certification is current, with Type II underway.

When your contract ends, you can request a full export of your data. After a grace period, all your data - along with any dedicated storage resources associated with your account - is permanently deleted according to our data retention policies.

Every AI interaction processed through Oximy is logged with full traceability. You can review exactly what data was sent, what policies were applied, what threats were detected, and what actions were taken. This audit trail supports your compliance requirements.

Oximy is SOC 2 Type I certified (with Type II underway), HIPAA compliant, and GDPR ready. We also align with OWASP LLM Top 10, NIST AI RMF, ISO 42001, MITRE ATLAS, AIUC-1, and EU AI Act requirements. Visit our Trust Center for detailed documentation.

Serious about security?

See how Oximy protects your AI systems while maintaining compliance with SOC 2, HIPAA, and GDPR.