Update cookies preferences
AI Governance

Set the rules. Enforce them everywhere.

Satisfy AI security standards with opt-in coverage and define custom policies in natural language to enforce rules across prompts, responses, and agent actions.

Get a demo
Illustration of a planet resembling Saturn with textured yarn-like swirling patterns in blue and purple and a yellow knitted ring around it.
Securing AI by the world's top providers

The Onyx Approach

Most AI governance requires security engineers to write rules in bespoke vendor-specific languages, security practitioners to describe what the policy should do, and compliance analysts to map it to a framework. None of them read the code that actually enforces it.

Onyx replaces the code-based bottleneck with natural language. Security teams write policies in natural language. Onyx compiles it into runtime enforcement and applies it across every current and future agent in scope, and across the MCP servers those agents reach. The platform refines the rule as the environment changes, so policy never drifts away from intent.

Starship model crafted entirely from knitted yarn in blue, purple, and gold colors.

The Onyx Difference

Floating icons representing code, users, and databases above a label saying Claude Code Agent.

Designed for the Agent Identity

When multiple users delegate to the same agent across tools, Onyx gives that agent its own identity, separate from the invoker. Govern, audit, and control one agent actor with one line of accountability, instead of reconciling scattered audit trails that only make sense one credential at a time.

Text: Agents can't be connected to Salesforce data and publicly accessible at the same time with Deploy Policy button.

Natural Language & Automated Compliance

Write policy in natural language and Onyx translates policy intent into runtime enforcement, with automatic mapping to OWASP LLM Top 10, NIST AI RMF, MITRE ATLAS, EU AI Act, and ISO 42001. No code required, so policy author and enforcer read from the same source of truth.

Interface showing toggle switches for Zendesk, Github, Clickup, and Figma MCP integrations, some enabled.

Complete Control Over Every Agent Tool

Specify the tools and MCP servers you trust, and block the rest. Onyx governs every agent tool, not just MCP: direct API calls, coding-agent hooks, base-URL integrations, and the MCP ecosystem all fall under one policy. When a new tool or server is detected, Onyx finds it, scores it for risk, and routes the approval decision before any agent uses it, keeping the trusted set current as the tool landscape grows.

See Onyx Connect to Your Stack

Onyx drops in next to the identity, cloud, network, and endpoint tools your team already runs. Most environments produce a working AI inventory within 24 hours and an enforced governance policy on day one. To see real-time AI security across your stack...

schedule a demo

Connects to the Tools You Already Run

Onyx integrates in two directions. Inbound, Onyx consumes identity context to attribute every policy decision. Outbound, alerts and their associated session records forward to your SIEM.

  • Every governed agent carries its own identity, aligned with the user behind it, giving every action a clear line of accountability from person to tool.
  • Violations and their session records synchronize with your SIEM, keeping compliance evidence and audit response in the tools your security and GRC teams already use.
  • Framework mappings for OWASP LLM Top 10, NIST AI RMF, MITRE ATLAS, EU AI Act, and ISO 42001 are applied automatically, so audit and regulator responses draw from the same policy record.
Illustration of a planet resembling Saturn with textured yarn-like swirling patterns in blue and purple and a yellow knitted ring around it.

Frequently Asked Questions

How does natural-language policy work?

You write the intent in plain English. Onyx compiles it into enforcement logic, applies it across every agent in scope, and logs every decision with a traceable record back to the original statement.

Which compliance frameworks does Onyx cover?

OWASP LLM Top 10, NIST AI RMF, MITRE ATLAS, EU AI Act, and ISO 42001.

How is per-agent identity governance different from standard IAM?

Standard IAM governs humans and service accounts. AI agents are neither. Each governed agent carries its own Onyx-attributed identity, distinct from the user who invoked it, and the same record tracks the per-tool-call and per-MCP-call identities the agent uses at each step.

How is this different from DLP or SASE?

DLP and SASE enforce at the network or file level. They were not built to inspect AI agent tool calls or apply policy logic the moment an action would execute. Onyx operates at the agent behavior layer and forwards alerts and sessions to your SIEM, extending your existing investigation surface rather than replacing it.