We use
self-hosted · local by default · policy in the request path · human approval · audit trail · receipt · evidence · data-processing agreement · subprocessor · designed to · built toward
Trust · Security, governance and compliance posture
Onega products are built to run in your environment. Inference stays local unless a route out is configured. Policy runs in the request path. People approve consequential actions. Every decision leaves a trail you own. We do not claim certifications we do not hold; we document controls and data flows per deployment.
01 — Posture
Onega products are built to run inside the customer's environment. Inference stays local unless a provider route is deliberately configured. Policy runs in the request path, not beside it. People approve consequential actions. Every decision leaves an evidence trail the customer owns. Onega does not claim certifications it does not hold; it documents controls, data flows and responsibilities per deployment.
02 — OneVeer
| Control | Detail |
|---|---|
| Local by default | Models run on the customer's CPU or GPU; a request leaves only through a configured provider route; a master switch disables all external providers; a request header pins a call local. |
| Policy in the path | Request rules, safety profiles and destinations are evaluated before routing and cache replay; policies are drafted, simulated against live decisions, activated as immutable revisions, and can be rolled back. |
| Kill switch | HMAC-SHA256 signed, replay-protected, scoped to everything, one agent or one model; enforced before any model is reached; durable across restarts; audited. |
| Guard models | Prompt Guard 2, ProtectAI DeBERTa v3, Llama Guard 3, Granite Guardian HAP inspect prompts, retrieved context and replies; a detector failure fails closed by default. |
| PII redaction | Emails, phone numbers, payment cards, IBANs, US social security numbers and IP addresses detected locally in Rust; observe, replace, mask, pseudonymise or deny. Detection is fallible. Zero findings means no configured recogniser matched, not that text is anonymous. OneVeer does not claim GDPR anonymisation, HIPAA de-identification or regulatory compliance. |
| Secrets | Provider credentials encrypted with AES-256-GCM, write-only in the console, protected by DPAPI on Windows; application keys stored as digests with grants, scopes, expiry and revocation. |
| Observability without leakage | OpenTelemetry and Prometheus export never carry prompts, completions, tool payloads, audio, images or keys. |
| Inventory | AI bill of materials exported as CycloneDX 1.6, CSV or a printable report. |
| Transport | No built-in TLS: OneVeer listens on plain HTTP inside the host and is deployed behind the customer's reverse proxy, where TLS terminates. |
03 — OneMail
| Control | Detail |
|---|---|
| Hosting | One organisation per installation, hosted by that organisation; Kubernetes-based; country data cells as residency boundaries; an air-gapped profile is designed. |
| Identity | Enterprise identity provider and SCIM provisioning; row-level security and fine-grained authorisation; default deny. |
| Decisions | AI proposes typed interpretations; deterministic policy validates identity, routing, authorisation and every side effect; automation levels L0–L4 per category, action and region; a guardrail breach downgrades automatically. |
| Evidence | Every recommendation carries confidence, highlighted source passages, attachment provenance, identity candidates, missing data and the rule and model versions used. |
| Actions | Deterministic action keys, an action ledger, connector idempotency, receipts and reconciliation prevent duplicate side effects; nothing reaches a customer or Dynamics 365 without an authorised decision and a receipt. |
| Audit | Append-only audit; prior decisions preserved as immutable events on re-evaluation. |
| Content safety | Links and attachments scanned; unsafe content quarantined; a self-hosted prompt-injection classifier. |
| Learning | Corrections feed versioned evaluation, shadow testing, canaries, approval, monitoring and rollback; no uncontrolled self-modification. |
04 — OneDesk
| Control | Detail |
|---|---|
| Architecture | Native desktop (Tauri 2, Rust); all state in encrypted local databases; a single master key in the operating system's credential store, every other secret in an encrypted vault; no backend service. |
| Network | Limited to the user's mail, calendar and contact providers and the model provider the user configures, plus public configuration lookups during account setup that send only the mailbox domain; local intelligence stays network-free. |
| AI authority | A device-wide AI kill switch in the persistent footer; a security kernel that answers no by default; drafts are prepared, never sent automatically; two-step confirmed send. |
| Fail-closed | Connected-content model inference and autonomous replies are disabled until the required security analyses are provisioned. |
05 — Engagements
06 — Regulation
Design intent, not certification.
07 — Security reports
Report a suspected vulnerability in OneVeer, OneDesk, OneMail or this website to support@onega.dev with “Security” in the subject. The same address is published in /.well-known/security.txt.
08 — Language
We use
self-hosted · local by default · policy in the request path · human approval · audit trail · receipt · evidence · data-processing agreement · subprocessor · designed to · built toward
We avoid
compliant · certified (of a product or control) · guaranteed · anonymised · zero-trust (unless describing a specific control) · military-grade · bank-level
09 — FAQ
Only where you configure it to. OneVeer keeps inference local by default, leaves only through a provider route you have configured and can pin any request local. OneDesk connects to your own mail, calendar and contact providers and to the model provider you configure, and during account setup looks up the mailbox domain’s public configuration; its local intelligence stays network-free. OneMail installs in your environment and takes mail from Exchange Online through Microsoft Graph.
Yes: OneVeer has a signed, scoped kill switch; OneDesk has a device-wide AI kill switch; OneMail is designed so that actions require authorised decisions and carry receipts.
We do not describe compliance as a product property. For each engagement we document the data flow, sign a data-processing agreement with a subprocessor list, and support redaction and deletion.
We do not hold ISO/IEC 27001, ISO/IEC 42001 or SOC 2 certification. We document controls, data flows and responsibilities for every deployment.