Trust · Security, governance and compliance posture

Inside your walls, by design.

Onega products are built to run in your environment. Inference stays local unless a route out is configured. Policy runs in the request path. People approve consequential actions. Every decision leaves a trail you own. We do not claim certifications we do not hold; we document controls and data flows per deployment.

01 — Posture

Posture in one paragraph.

Onega products are built to run inside the customer's environment. Inference stays local unless a provider route is deliberately configured. Policy runs in the request path, not beside it. People approve consequential actions. Every decision leaves an evidence trail the customer owns. Onega does not claim certifications it does not hold; it documents controls, data flows and responsibilities per deployment.

02 — OneVeer

Controls in OneVeer.

OneVeer
ControlDetail
Local by defaultModels run on the customer's CPU or GPU; a request leaves only through a configured provider route; a master switch disables all external providers; a request header pins a call local.
Policy in the pathRequest rules, safety profiles and destinations are evaluated before routing and cache replay; policies are drafted, simulated against live decisions, activated as immutable revisions, and can be rolled back.
Kill switchHMAC-SHA256 signed, replay-protected, scoped to everything, one agent or one model; enforced before any model is reached; durable across restarts; audited.
Guard modelsPrompt Guard 2, ProtectAI DeBERTa v3, Llama Guard 3, Granite Guardian HAP inspect prompts, retrieved context and replies; a detector failure fails closed by default.
PII redactionEmails, phone numbers, payment cards, IBANs, US social security numbers and IP addresses detected locally in Rust; observe, replace, mask, pseudonymise or deny. Detection is fallible. Zero findings means no configured recogniser matched, not that text is anonymous. OneVeer does not claim GDPR anonymisation, HIPAA de-identification or regulatory compliance.
SecretsProvider credentials encrypted with AES-256-GCM, write-only in the console, protected by DPAPI on Windows; application keys stored as digests with grants, scopes, expiry and revocation.
Observability without leakageOpenTelemetry and Prometheus export never carry prompts, completions, tool payloads, audio, images or keys.
InventoryAI bill of materials exported as CycloneDX 1.6, CSV or a printable report.
TransportNo built-in TLS: OneVeer listens on plain HTTP inside the host and is deployed behind the customer's reverse proxy, where TLS terminates.

03 — OneMail

Controls designed into OneMail.

OneMail
ControlDetail
HostingOne organisation per installation, hosted by that organisation; Kubernetes-based; country data cells as residency boundaries; an air-gapped profile is designed.
IdentityEnterprise identity provider and SCIM provisioning; row-level security and fine-grained authorisation; default deny.
DecisionsAI proposes typed interpretations; deterministic policy validates identity, routing, authorisation and every side effect; automation levels L0–L4 per category, action and region; a guardrail breach downgrades automatically.
EvidenceEvery recommendation carries confidence, highlighted source passages, attachment provenance, identity candidates, missing data and the rule and model versions used.
ActionsDeterministic action keys, an action ledger, connector idempotency, receipts and reconciliation prevent duplicate side effects; nothing reaches a customer or Dynamics 365 without an authorised decision and a receipt.
AuditAppend-only audit; prior decisions preserved as immutable events on re-evaluation.
Content safetyLinks and attachments scanned; unsafe content quarantined; a self-hosted prompt-injection classifier.
LearningCorrections feed versioned evaluation, shadow testing, canaries, approval, monitoring and rollback; no uncontrolled self-modification.

04 — OneDesk

Controls in OneDesk.

OneDesk
ControlDetail
ArchitectureNative desktop (Tauri 2, Rust); all state in encrypted local databases; a single master key in the operating system's credential store, every other secret in an encrypted vault; no backend service.
NetworkLimited to the user's mail, calendar and contact providers and the model provider the user configures, plus public configuration lookups during account setup that send only the mailbox domain; local intelligence stays network-free.
AI authorityA device-wide AI kill switch in the persistent footer; a security kernel that answers no by default; drafts are prepared, never sent automatically; two-step confirmed send.
Fail-closedConnected-content model inference and autonomous replies are disabled until the required security analyses are provisioned.

05 — Engagements

Data handling in an engagement.

  • Data-flow map before any data is processed: sources, destinations, retention, access roles, model destinations, subprocessors.
  • Data-processing agreement for the actual flow, signed with the engagement; Onega as processor where it operates a workflow, as vendor where it licenses software.
  • No production access before written authorisation; sandboxes and approved samples first.
  • Logging, retention and deletion defined per engagement and written into the runbook.
  • Incident path with named contacts on both sides; stop conditions agreed in advance.

06 — Regulation

Regulatory alignment.

Design intent, not certification.

  • GDPR: local processing, redaction, deletion support, DPA and subprocessor list per deployment.
  • EU AI Act: use-case classification in discovery; human oversight designed in; decision logging; AI bill of materials; high-risk categories declined.
  • NIS2 / DORA: documented incident handling, update process, third-party dependency reduction through self-hosting, kill switch and audit trail for regulated customers.
  • Accessibility: OneMail built to WCAG 2.2 AA with RTL; conformance claims require an audit.

07 — Security reports

Vulnerability disclosure.

Report a suspected vulnerability in OneVeer, OneDesk, OneMail or this website to support@onega.dev with “Security” in the subject. The same address is published in /.well-known/security.txt.

08 — Language

Words we use and words we avoid.

We use

self-hosted · local by default · policy in the request path · human approval · audit trail · receipt · evidence · data-processing agreement · subprocessor · designed to · built toward

We avoid

compliant · certified (of a product or control) · guaranteed · anonymised · zero-trust (unless describing a specific control) · military-grade · bank-level

09 — FAQ

Frequently asked questions.

Does my data leave my environment?

Only where you configure it to. OneVeer keeps inference local by default, leaves only through a provider route you have configured and can pin any request local. OneDesk connects to your own mail, calendar and contact providers and to the model provider you configure, and during account setup looks up the mailbox domain’s public configuration; its local intelligence stays network-free. OneMail installs in your environment and takes mail from Exchange Online through Microsoft Graph.

Can we stop it?

Yes: OneVeer has a signed, scoped kill switch; OneDesk has a device-wide AI kill switch; OneMail is designed so that actions require authorised decisions and carry receipts.

Are you GDPR compliant?

We do not describe compliance as a product property. For each engagement we document the data flow, sign a data-processing agreement with a subprocessor list, and support redaction and deletion.

Are you certified?

We do not hold ISO/IEC 27001, ISO/IEC 42001 or SOC 2 certification. We document controls, data flows and responsibilities for every deployment.