Trust & Security

Your data. Your workspace. It stays yours.

OYNYX handles your customers without ever touching your systems. Here’s exactly how your data is separated, protected, and handed back — what’s enforced today, and what hardens as the platform matures.

The scope wall

We handle your customers. Your team does the work only they can do.

The same wall applies to every tier, every industry, every client. It is the first thing we agree at onboarding and the last thing that changes.

We doThe client experience
Capture every contact, on every channel.
Qualify, triage and route by urgency.
Follow up to resolution — not to message-passed.
Send confirmations, reminders and status updates.
Check in with your customers proactively.
Track at-risk accounts and flag them.
Run jobs with professionals from the PartnerConnect™ network.
Deliver monthly Insights with a recommendation.
Update the Playbook from what the data reveals.
SCOPE WALL
Your team keepsYour team’s judgment
The legal calls and legal advice.
The medical decisions.
Who goes where on a job.
Your internal operations.
Your systems — we book through the link you share.
Your logins, passwords and calendar credentials.
Your payment card data.
Every business decision.

The boundary in one sentence. We own the client experience — the contact, the follow-through, the retention outreach, the reporting. Your team owns the judgment — the legal call, the medical decision, who goes where on a job, the business strategy.

Data posture

Four tiers of data. Three of them are yours to see. One never reaches us.

What we hold, why we hold it, and where it stops — set out tier by tier rather than summarised in a sentence you would have to trust.

Inside the wall Held in your workspace · exportable at any time
Tier A

Contact metadata

Name, contact details, channel, timestamp, qualification, urgency, tag, assigned specialist — the minimum needed to handle a contact.

Stored in the workspace.

We hold this
Tier B

Interaction data

The conversation itself — what the AI said, what the specialist said, what your customer said. Internal notes, resolution notes, follow-up history.

Logged against the customer record.

We hold this
Tier C

Shared workspace data

Work items, statuses, deadlines, vendor job records, Insights reports, Playbook content, appointments booked through your shared link.

Your data, in your workspace, visible to you at all times.

We hold it · you see it
STAYS WITH YOU
Tier D · outside the wall

Stays in your own systems

Your system credentials Payment card numbers Internal financial records Medical records, until our HIPAA compliance program and Business Associate Agreements are in place Attorney–client privileged content Anything that belongs inside your own systems

We hand clean data back. We never reach in.

Isolation and accountability

Separated by assignment and contract. Recorded so you can check it.

Two claims that would be worthless as promises, so neither is one. Each is shown twice: what enforces it today, and what hardens it when the platform is live.

Your workspace

Worked only by the specialists assigned to your account.

ASSIGNMENT
Any other client

A different Playbook, a different workspace, a different assignment record.

The line is drawn by assignment and contract today. At platform launch it is redrawn inside the database itself — same boundary, enforced a level lower down.
Isolation
In force today

Access is assignment-based. Only the specialists assigned to your account work in your workspace, and no other OYNYX team member is given access without an explicit assignment that is documented.

The four tiers are contractual. What we hold, what you see and what we never touch is written into your agreement and carried in the Playbook — not left to convention.

Credentials live in a password vault, revocable and never in a shared document or a specialist’s memory. Crossing the scope wall is a critical-fail QA category: a firing condition, not a guideline.

On platform launch

Row-level security. The policy is attached to the table itself rather than to application logic, so a client’s rows are scoped at the database layer whatever the query asks for. Designed into the architecture; deployed when the ClientConnect™ platform is live.

Accountability
In force today
Contact handled · specialist · timestamped
Assignment changed · recorded
Playbook changed · date, change, trigger

Activity logging is on across contact handling, escalation, data access, Playbook changes and configuration — who, when, what — and reviewable by you on request. Ask who had access to your account on 3 September and we can answer it.

The Playbook change log is visible inside your workspace: every update with its date, the change and what triggered it.

On platform launch

An append-only, cryptographically chained trail across five categories of event, not editable after the fact, seven-year retention, and yours to pull whenever you want.

Contact handlingEscalationData accessPlaybook changesSystem configuration
Both columns answer the same question — who had access, and what happened — and the answer is one you can show your team, your customer, a regulator or a court. What changes at launch is how hard it is to dispute.
Protection

Encrypted at rest. Encrypted in transit. MFA for everyone.

The baseline every account starts with — in place before your first contact is handled, with no exceptions and no opt-outs, including for our own staff.

Before your first contact is handled

Encrypted at rest

Industry-standard encryption on everything stored, backups included.

Encrypted in transit

Every connection over TLS. No exceptions, no downgrade path.

Secrets in a vault

API keys and credentials held in a vault, never in client-accessible code.

MFA required

Multi-factor authentication for every user — yours and ours. Enforced, not requested.

Compliance

What is in force, what arrives before it is needed, and what is still in progress.

Three regulatory postures at three different stages. We label which is which, because alignment is not certification and you should not have to guess.

Confidentiality ABA Model Rules discipline In force today

Rule 1.6, confidentiality. Client data is never shared, disclosed or used outside the scope of the engagement.

Rule 5.3, supervision. Every specialist handling a legal client’s contacts operates under Playbook rules the firm has reviewed and approved.

OYNYX is not a law firm and does not give legal advice — the scope wall is what enforces that, not a promise.

Health information HIPAA readiness Before health data is handled

Before any health information is handled, OYNYX will operate under a Business Associate Agreement, and Protected Health Information will be handled to HIPAA requirements — access controls, audit logging, encryption, minimum necessary standard.

The infrastructure is being built for it. Our HIPAA compliance program and Business Associate Agreements are not yet in place, and until they are, medical records sit outside the wall.

Security controls SOC 2 Type II alignment In progress

The platform is being built to SOC 2 Type II controls — access control, logging, encryption, change management, incident response.

Alignment is not certification. Formal audit will be pursued as the client base reaches enterprise accounts, and we will say so here when it is done.

Compliance is configured per account in your Client Playbook. A Playbook under the ABA Model Rules carries that discipline; one that handles health information will carry HIPAA rules. The system adapts to your regulatory environment rather than averaging across it.
Portability

Your data leaves freely. Nothing of ours reaches in.

The wall is not one-directional by accident. Data crossing outward is a one-click export; access crossing inward is the line we never cross.

Your side Your systems, your logins

Your CRM, calendar backend, email server, practice software. We book through a shared public link you give us at onboarding — never a backend login.

Your data, out
Our access, in×
Our side The workspace we run

Every action happens in our system, which is exactly why every action is in our audit trail. The boundary is the design, not a limitation.

Full export, one click

Every customer record, interaction, work item and Insights report. No waiting period, no exit fee, no format lock-in.

CSVJSONPDF

Structured hand-back

On the schedule your Playbook sets — daily, weekly, or pushed in real time for emergencies. Structured so your team can paste it straight into your own systems.

We never ask for your logins. If you leave, you leave with the complete record. The workspace is yours — we hold it, we don’t own it.

Get started

Built for work that can’t leak.

Book a walkthrough — we’ll show you the scope wall, the data posture, and exactly where your team’s side begins.