The current control posture, stated plainly.

Security decisions are recorded for the specific deployment. Onyx Intel does not claim HIPAA, SOC 2, or another certification unless a current written record supports it.

Transport and access

  • HTTPS/TLS for browser traffic
  • Authenticated product routes
  • Role and firm scope applied to workflow access
  • Explicit human review before consequential output

Traceability

  • Source-linked workflow state
  • Visible exception and review status
  • Audit events for supported product actions
  • Controlled download and handoff boundaries

Deployment decisions

  • Permission and matter-visibility map
  • Retention and deletion schedule
  • Backup and recovery objectives
  • Subprocessor and secure-transfer record
  • Incident contacts and offboarding plan

Leave the review with a written control record.

The record should identify the deployment owner, hosting environment, encryption in transit, access model, backup approach, audit coverage, retention and deletion decisions, incident contacts, participating vendors, and any open items.

No confidential client records are needed for the initial product or security conversation.

Share review requirements