1. Who we are
Onyx (“Onyx”, “we”, “us”) is an API security testing platform operated by [Legal Entity Name]. This policy explains what data we handle and why. Questions? Contact privacy@[your-domain].
2. Information we collect
Account information
When you create an account we store your email address and, optionally, a display name. If you register with a password, we store only a one-way bcrypt hash of it — never the password itself. If you sign in with Google or GitHub, we store the identifier those providers return so we can recognize you; we do not receive your Google/GitHub password.
Scan data
To run a scan we store the target API specification URL and the endpoints we discover from it, plus the results of each attack request: HTTP method, path, the payload sent, response status code, and latency. We also store a short response snippet as evidence — this is redacted to mask secrets (bearer tokens, API keys, passwords) and capped in length before it is written to our database, so raw credentials are not persisted.
Credentials for authenticated scans
If you configure an authentication recipe (for scanning behind a login), the secret value is encrypted at rest using authenticated AES-256-GCM encryption. We retain only non-secret descriptors (such as the header/cookie name and the last four characters) for display; the full secret is never returned to the UI or written to logs.
API tokens
Long-lived API tokens for the CLI and CI are stored only as SHA-256 hashes. The plaintext token is shown to you once at creation and never stored; you can revoke a token at any time.
Billing information
Payments are processed by Razorpay. We do not store your card or bank details; we retain your plan, a Razorpay subscription identifier, the plan expiry, and the identifiers of billing webhook events we receive.
Usage & analytics
Our website uses Vercel Analytics and Speed Insights to understand aggregate, privacy-friendly usage and performance. We do not use these to build advertising profiles.
3. How we use your information
- To provide the service — run scans, stream results, and generate reports.
- To authenticate you and secure your account.
- To process subscriptions and billing.
- To operate, debug, and improve the platform.
- To communicate service-related notices.
Our legal basis for processing (where applicable, e.g. GDPR) is performance of our contract with you, your consent, and our legitimate interest in operating and securing the service. [Confirm legal-basis framing for your jurisdiction.]
4. Third-party processors
We share data with the following providers only as needed to run Onyx:
- Neon — managed PostgreSQL database (your account and scan data).
- Upstash / Redis — the job queue that schedules scan work.
- Render — hosting for the API/backend.
- Vercel — hosting for the web app, plus analytics and speed insights.
- Razorpay — payment processing for subscriptions.
- Google and GitHub — optional OAuth sign-in.
- Google Gemini — generates schema-aware attack payloads from your API specification. Endpoint descriptors from your spec are sent to Gemini for this purpose.
Each processor handles data under its own terms and security controls. We do not sell your personal information.
5. Data retention
We retain account data for as long as your account is active. Scan data and their (redacted, length-capped) response snippets are retained so you can review past reports; deleting a test run removes its associated attack logs. You may request deletion of your account and associated data (see “Your rights”).[Set concrete retention periods.]
6. Security
We apply encryption at rest for authentication secrets (AES-256-GCM), store tokens and passwords only as hashes, redact secrets from stored evidence, and enforce an SSRF guard and domain-ownership verification so scans only reach targets you own. See our Security page for details. No method of transmission or storage is 100% secure.
7. Your rights
Depending on your location, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these, contact privacy@[your-domain]. We will respond within the timeframe required by applicable law.
8. Children
Onyx is not directed to individuals under 18, and we do not knowingly collect personal data from them.
9. International transfers
Our processors may store or process data in regions outside your own. Where required, we rely on appropriate safeguards for such transfers. [Confirm transfer mechanism.]
10. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by an updated effective date, and where appropriate we will notify you.
11. Contact
Questions about this policy or your data: privacy@[your-domain], operated by [Legal Entity Name], [Address].