Your data is in safe hands
From encryption to access control, we enforce rigorous standards to keep your data secure, private, and compliant.
Certified & Compliant
Certified and compliant with rigorous international standards
SOC 2 Type I
Independently audited for security, availability, and confidentiality. Type II certification currently underway.
HIPAA
Fully compliant with healthcare data protection requirements. BAAs available for enterprise customers.
GDPR
Full compliance with EU data protection regulations. DPAs available upon request.
Enterprise-Grade Security
Built for security from day one
Your data is protected at every layer - from encryption to access control to audit logging.
Data Encryption
All data encrypted in transit (TLS 1.3) and at rest (AES-256). Your data is protected at every layer.
Flexible Hosting
Choose where your data lives: US-based, EU-based, or fully on-premises deployment to meet your compliance needs.
No Model Training
We contractually guarantee your data is never used to train AI models. Your inputs, outputs, and documents remain exclusively yours.
SSO & Access Control
Enterprise SSO support with SAML 2.0 and OIDC. Fine-grained role-based access control ensures the right people have the right access.
Comprehensive Audit Logs
Every action is logged and traceable. Full visibility into who accessed what, when, and from where for compliance reviews.
Annual Penetration Testing
We partner with top-tier security firms for annual penetration tests to proactively identify and mitigate risks.
Zero Trust Architecture
No user or system is inherently trusted. Access is always verified, limited, and logged following Zero Trust principles.
Data Retention Policies
Set and manage data retention periods aligned with your internal policies and regulatory requirements via our Trust Center.
AI Security Standards
Aligned with major AI security frameworks
Oximy helps you meet the requirements of leading AI security and governance frameworks. We continuously update our platform as standards evolve.
OWASP LLM Top 10
Protection against all 10 critical LLM vulnerabilities
NIST AI RMF
Aligned with the NIST AI Risk Management Framework
ISO 42001
AI management system standards alignment
MITRE ATLAS
Defense against adversarial AI attack techniques
AIUC-1
AI User Controls standard compliance
EU AI Act
Ready for European AI regulatory requirements
Continuous Compliance
Our platform evolves with the AI security landscape
6+
Frameworks
100%
Coverage
24/7
Monitoring
Security FAQs
All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption. For customers who require additional control, we offer options to encrypt data with their own encryption keys (BYOK). Your data is protected at every layer of our infrastructure.
We offer flexible hosting options to meet your compliance needs. Choose between US-based hosting, EU-based hosting, or on-premises deployment. Data never leaves your chosen region, and we can provide documentation for regulatory requirements.
No, never. We contractually guarantee through our Security Addendum that your data stays yours. We do not use your inputs, outputs, or uploaded documents to train or fine-tune any AI models. Your confidential data remains secure and private.
We support enterprise SSO with SAML 2.0 and OIDC protocols, giving you full control over user authentication. Our role-based access control (RBAC) ensures users only have access to what they need. All access is logged and auditable.
We partner with top-tier security firms for annual penetration tests covering the full platform scope. We follow an 'assume breach' methodology to proactively identify and mitigate risks. Our SOC 2 Type I certification is current, with Type II underway.
When your contract ends, you can request a full export of your data. After a grace period, all your data - along with any dedicated storage resources associated with your account - is permanently deleted according to our data retention policies.
Every AI interaction processed through Oximy is logged with full traceability. You can review exactly what data was sent, what policies were applied, what threats were detected, and what actions were taken. This audit trail supports your compliance requirements.
Oximy is SOC 2 Type I certified (with Type II underway), HIPAA compliant, and GDPR ready. We also align with OWASP LLM Top 10, NIST AI RMF, ISO 42001, MITRE ATLAS, AIUC-1, and EU AI Act requirements. Visit our Trust Center for detailed documentation.
Serious about security?
See how Oximy protects your AI systems while maintaining compliance with SOC 2, HIPAA, and GDPR.