The short version: Onyx is self-hosted. Your policies, requests, decisions, certificates, and audit trails live in your infrastructure and are processed there. The Onyx Foundry does not receive them.
Onyx runs on infrastructure you control. When you connect an MCP client — such as Claude — to your Onyx server, traffic flows directly between your client and your server. The Onyx Foundry operates no intermediary service in that path and receives no policy content, request content, decision data, or audit-trail data. Proof certificates and hash-chained trails are generated and stored on your systems and are re-verifiable there without contacting us.
Only what you choose to send us — for example, email to contact@onyxfoundry.ai or a request for demo access. We use it to respond and to operate the business, retain it only as long as that requires, and do not sell it or share it with anyone except the service providers below or where the law requires.
Write to contact@onyxfoundry.ai to ask what correspondence we hold from you or to request its deletion. Security reports: security.txt.
Updates to this policy are posted on this page with a new effective date.