Security
Last updated: January 1, 2026
Security is foundational to a managed AI workforce. This page describes the controls and practices Onita uses to protect your data across the platform we build, host, and run for you.
Encryption
Data is encrypted in transit using TLS and at rest using industry-standard encryption. Secrets and credentials are stored in dedicated, access-controlled vaults.
Access controls and permissions
Every AI agent operates within scoped permissions that bound exactly what it can read and do. Role-based access control governs what people on your team can see and manage.
Human-in-the-loop approvals
Sensitive and client-facing actions require human approval. You decide where approval gates sit, and agents never take gated actions without sign-off.
Audit logging
Every action an agent takes is logged, giving you a complete, reviewable record of what happened, when, and why.
Data ownership and residency
With Onita Private, we deploy and run a dedicated instance in your own environment so your data stays under your ownership and control, meeting strict residency and compliance requirements.
Compliance and reporting
We align our practices with recognized frameworks including SOC 2. To request our security documentation or report a concern, contact hello@onitaai.com.