Financial data, handled like it
Ontu is used on live deals and client engagements. This page is the current posture, stated plainly — including what isn't done yet.
How your data is protected
Encryption in transit and at rest
All traffic over TLS. Data at rest is encrypted by the hosting and storage layers.
Token encryption
OAuth tokens for connected mailboxes are encrypted at the application layer before storage.
Access scoped by project
Team members see only the projects they're a member of. Correspondence and documents are partitioned per project.
No model training on your data
Content sent to model providers for inference is not used to train their models.
Where we are today
Your data isn't training data
Content sent to model providers for inference is never used to train their models, and ontu does not train on your content.
GDPR & CCPA
Built to support your obligations under GDPR and CCPA, including data-subject requests and deletion.
ISO 27001 & SOC 2
Independent audits are on the roadmap. ontu is not certified today and does not claim to be.
Who else touches the data
- RailwayApplication hosting and Postgres database (US region).
- Cloudflare R2Encrypted object storage for uploaded documents.
- AssemblyAISpeech-to-text for uploaded call recordings.
- Microsoft GraphSending and reading mail on connected Microsoft 365 mailboxes.
- Anthropic / OpenAIModel inference for drafting and analysis. No training on your data.
This list is kept current. Material changes are communicated to customers in advance.
See Ontu on your next project
A short walkthrough with your deal team. No slideware, just the product on a real workflow.