Enterprise security, built for AI.
Oximy sees the AI your company already runs on so you can make it work better. The controls exist to protect that work, not to police the people doing it.
Not a monitoring product.
Oximy is built to help teams use AI well. The point of the map is to understand which tools, accounts, workflows and model traffic a company runs on, so better defaults can be made available to everyone.
Customer data is not used to train shared models. Provider retention settings can be enforced through policy, and every routing decision is recorded so the reasoning behind it stays inspectable.
SOC 2 Type II
Oximy is independently audited for security, availability, and confidentiality against SOC 2 Type II.
HIPAA
Administrative, technical, and physical safeguards support organizations handling protected health information. BAAs are available where applicable.
GDPR
Privacy controls, data-processing agreements, and secure handling of personal data support GDPR requirements.
Bring Your Own Keys
Keep control of provider credentials and encryption keys while using centralized routing and policy.
Complete Audit Logs
Track tools, requests, routing decisions, workflow changes, and administrative actions.
Flexible Deployment
Choose regional cloud, private networking, or enterprise deployment patterns that fit your environment.
End-to-End Encryption
Every AI request is encrypted in transit (TLS 1.3) and at rest (AES-256) to protect data across every interaction.
Identity & Access
SSO, role-based access, and team-level policy make permissions explicit and auditable.
AI Policy Controls
Apply provider, model, data, workflow, and retention policy at the point of every request.
Built against the standards your auditors already use.
- OWASP LLM Top 10
- Protection against all 10 critical LLM vulnerabilities
- ISO 42001
- AI management system standards alignment
- NIST AI RMF
- Aligned with the NIST AI Risk Management Framework
- MITRE ATLAS
- Defense against adversarial AI attack techniques
- AIUC-1
- AI User Controls standard compliance
- EU AI Act
- Ready for European AI regulatory requirements
Common questions.
No. Customer data is not used to train shared models, and provider retention settings can be enforced through policy.
Yes. Regional and private networking options are available to support residency and enterprise infrastructure requirements.
Yes. Relay records provider, model, policy, quality, latency, and cost signals for every routing decision.