Skip to main content
Get a demo
Security

Enterprise security, built for AI.

Oximy sees the AI your company already runs on so you can make it work better. The controls exist to protect that work, not to police the people doing it.

Not a monitoring product.

Oximy is built to help teams use AI well. The point of the map is to understand which tools, accounts, workflows and model traffic a company runs on, so better defaults can be made available to everyone.

Customer data is not used to train shared models. Provider retention settings can be enforced through policy, and every routing decision is recorded so the reasoning behind it stays inspectable.

SOC 2

SOC 2 Type II

Oximy is independently audited for security, availability, and confidentiality against SOC 2 Type II.

HIPAA

HIPAA

Administrative, technical, and physical safeguards support organizations handling protected health information. BAAs are available where applicable.

GDPR

GDPR

Privacy controls, data-processing agreements, and secure handling of personal data support GDPR requirements.

Bring Your Own Keys

Keep control of provider credentials and encryption keys while using centralized routing and policy.

REQUESTRESPONSEYOUR KEYSYOUR ACCOUNTMODEL PROVIDER

Complete Audit Logs

Track tools, requests, routing decisions, workflow changes, and administrative actions.

EVERY REQUESTAPPEND-ONLY LOG

Flexible Deployment

Choose regional cloud, private networking, or enterprise deployment patterns that fit your environment.

CLOUDMANAGEDREGIONALYOUR REGIONON-PREMYOUR METAL

End-to-End Encryption

Every AI request is encrypted in transit (TLS 1.3) and at rest (AES-256) to protect data across every interaction.

Identity & Access

SSO, role-based access, and team-level policy make permissions explicit and auditable.

AI Policy Controls

Apply provider, model, data, workflow, and retention policy at the point of every request.

Frameworks

Built against the standards your auditors already use.

OWASP LLM Top 10
Protection against all 10 critical LLM vulnerabilities
ISO 42001
AI management system standards alignment
NIST AI RMF
Aligned with the NIST AI Risk Management Framework
MITRE ATLAS
Defense against adversarial AI attack techniques
AIUC-1
AI User Controls standard compliance
EU AI Act
Ready for European AI regulatory requirements

Common questions.

No. Customer data is not used to train shared models, and provider retention settings can be enforced through policy.

Yes. Regional and private networking options are available to support residency and enterprise infrastructure requirements.

Yes. Relay records provider, model, policy, quality, latency, and cost signals for every routing decision.