Security architecture

Know what every AI request can see, change—and what happened next.

Onterix checks who is acting, what data can leave, which action is allowed, whether a retry is safe, and what result the destination confirmed.

One redacted run

See the security decision and the evidence behind it.

This customer-renewal example shows the five questions with concrete data, approval, execution, and receipt evidence. The same decisions apply to a person using an AI client, an autonomous agent, or an application.

Run otr_01JQ9F42 · redacted view

Customer renewal through Codex.

Follow one request from the person’s current authority through data release, exact approval, safe execution, and destination receipts.

01 · What is the current authority?
Check who is acting, which client they use, whose access they represent, and what current source permissions allow.
Example · Maya Chen · person · Codex MCP client · current Salesforce access · renewal policy v7.
02 · What may AI receive?
Inspect source results before release. Minimize, mask, tokenize, or transform data for the intended recipient and destination.
Example · Retrieved: account, opportunity stage, renewal date, buyer contact, and private note. Released: the first four fields; the private note was withheld by release rule v4.
03 · What exact change is allowed?
Bind approval to the record, current value, proposed value, recipient, reviewer, and request digest. A material change requires a new approval.
Example · Salesforce opportunity stage 2 → 3 and one reviewed follow-up to the named buyer, approved by Revenue Operations for this exact request.
04 · What happened before another attempt?
Check the destination to learn whether the first attempt succeeded. Repeat an action only when current state shows it is safe.
Example · CRM read-back found stage 3 already applied. The email provider reported the message accepted, so Onterix did not write or send again.
05 · What result was confirmed?
Keep the request, decisions, attempts, provider responses, and confirmed result connected without copying secrets or full source payloads into the audit trail.
Example · Salesforce and email-provider receipts were retained under run otr_01JQ9F42 with the policy, release, transform, and approval versions.

Decision evidence

Keep an inspectable evidence chain from request to result.

Onterix records safe summaries, hashes, versioned decisions, approvals, provider references, and final status while secrets remain outside the audit trail.

  1. WHORequest, actor, client, and current authorityauthority
  2. DATARetrieved data, transforms, what AI received, and destinationrelease
  3. APPROVEExact old and new values, recipient, reviewer, and bindingdecision
  4. EXECUTEAttempts, provider references, and reconciliationexecution
  5. RESULTConfirmed destination state and receiptoutcome

Your security stack

Keep the systems you already trust.

Connect your identity, DLP, key management, model gateway, secrets, SIEM, and storage providers. The runtime uses them to decide what each run may access, release, and change.

Security review

Trace one real workflow from request to result.

Bring its systems, data, actions, approvers, and deployment requirements.