Controlled testing requires explicit boundaries.
Oxyne is built to test authorized systems and preserve reviewable evidence. This page describes verified safeguards and current limitations—not a certification or substitute for customer security diligence.
Verified, authorized targets
Customer targets and supported system interfaces are scoped and verified before real testing. The engagement defines permitted actions and prohibited impact.
Bounded live testing
Deeper campaigns use explicit authorization, bounded execution, safety controls, full logging, and admin-gated workflows for live targets.
Evidence and audit trail
Oxyne retains scan events, supporting conversation transcripts, judge reasoning, and assessment evidence so findings can be reviewed and replayed.
Organization-scoped access
Product routes and data access are scoped through authenticated organization context and authorization checks. Public marketing access is separate from the product dashboard.
Confirm deployment and data requirements during scoping.
Private VPC, on-premises, and air-gapped deployments are not standard supported offerings today.
Connector support and safe test depth vary by target interface and authorized actions.
Framework mappings are directional technical references, not certifications or audit opinions.
Data-processing, retention, model-provider, and procurement requirements should be confirmed in writing for the specific engagement.
Report a security concern privately.
If you believe you have found a vulnerability in an Oxyne-owned system, email hello@oxyne.ai with “Security disclosure” in the subject. Do not access customer data, disrupt service, or test third-party targets without written authorization.
See Oxyne on your own systems.
Book a 30-minute walkthrough — we'll scope a real assessment for your AI and web surfaces.