Trust Center

Financial data, handled like it

Ontu is used on live deals and client engagements. This page is the current posture, stated plainly — including what isn't done yet.

Data handling

How your data is protected

Encryption in transit and at rest

All traffic over TLS. Data at rest is encrypted by the hosting and storage layers.

Token encryption

OAuth tokens for connected mailboxes are encrypted at the application layer before storage.

Access scoped by project

Team members see only the projects they're a member of. Correspondence and documents are partitioned per project.

No model training on your data

Content sent to model providers for inference is not used to train their models.

Current posture

Where we are today

Your data isn't training data

Content sent to model providers for inference is never used to train their models, and ontu does not train on your content.

GDPR & CCPA

Built to support your obligations under GDPR and CCPA, including data-subject requests and deletion.

ISO 27001 & SOC 2

Independent audits are on the roadmap. ontu is not certified today and does not claim to be.

Sub-processors

Who else touches the data

  • RailwayApplication hosting and Postgres database (US region).
  • Cloudflare R2Encrypted object storage for uploaded documents.
  • AssemblyAISpeech-to-text for uploaded call recordings.
  • Microsoft GraphSending and reading mail on connected Microsoft 365 mailboxes.
  • Anthropic / OpenAIModel inference for drafting and analysis. No training on your data.

This list is kept current. Material changes are communicated to customers in advance.

Get started

See Ontu on your next project

A short walkthrough with your deal team. No slideware, just the product on a real workflow.