Skip to content
Onita AI

Security

Last updated: 24 August 2026

Security is foundational to how Onita AI works. This page summarises the controls and practices we use to protect your data; for full detail on how we handle information, see our Privacy Policy.

Encryption

Data is encrypted in transit using HTTPS across the Service. Sensitive credentials — such as connected-account tokens and API keys — are encrypted while stored, and passwords are kept only as strong, one-way hashes that we can never read.

Access controls and permissions

Every AI agent operates within scoped permissions that bound exactly what it can read and do. Access controls ensure that only authorised people and systems can reach your data, and you decide what your agents and teammates are allowed to do.

Human-in-the-loop approvals

Sensitive and client-facing actions can be held for human approval. You decide where approval gates sit, and agents do not take gated actions without sign-off.

Audit logging and history

Actions taken in your workspace are recorded with an audit trail of changes and approvals, giving you a reviewable record of what happened and when.

Secure operations

We apply rate limiting on sensitive actions, redact secrets from our logs, and choose infrastructure and AI providers that offer strong security and confidentiality terms. Your data is hosted with reputable cloud providers; see our Privacy Policy for where data is processed.

Reporting a concern

No online service can be perfectly secure. If you discover a vulnerability or suspect unauthorised access to your account, contact us at legal@onitaapp.com, and protect your account by keeping your password confidential and using human-approval controls for sensitive actions.