Public-source research
Vendor evidence
Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.
Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6
Onyx AI claims a approved self-hosted enterprise AI platform with organization and group sharing, permissions, usage analytics, model controls, auditability, and governed access to enterprise knowledge and actions.
Give your team an approved AI platform that actually works, so they stop pasting company data into ChatGPT.
Related framework references (5)
Onyx AI materials reviewed did not provide a public product claim for automated adversarial testing, repeatable attack suites, model or agent red teaming, or release-gate evaluation.
No quoted source text is recorded for this claim.
Related framework references (5)
Onyx AI materials reviewed did not establish model artifact scanning, provenance, signing, dependency or Model Context Protocol (MCP) component analysis, tamper detection, or model-registry release controls.
No quoted source text is recorded for this claim.
Related framework references (5)
Onyx AI claims configurable agents with controlled Actions, data access, knowledge sources, and the ability for administrators to enable or disable Model Context Protocol (MCP) and OpenAPI actions.
Users have the flexibility to turn on or off the Actions that the Agent or LLM has access to.
Related framework references (5)
Onyx AI claims organization and group-based agent sharing plus configurable knowledge and action permissions for enterprise agents.
Publish your Agent to your entire organization or share it with specific users or groups.
Related framework references (5)
Onyx AI materials reviewed did not establish governance of coding-agent commands, developer-workstation files or networks, integrated development environment (IDE) extensions, skills, hooks, secrets, or package actions.
No quoted source text is recorded for this claim.
Related framework references (5)
Onyx claims it can reduce shadow AI by giving users an approved AI platform, but it does not publicly claim independent discovery of third-party AI usage outside Onyx.
Give your team an approved AI platform that actually works, so they stop pasting company data into ChatGPT.
Related framework references (5)
No public claim found for this capability.
No quoted source text is recorded for this claim.
Related framework references (5)
Onyx claims usage analytics, query logs, feedback tracking, and query history for activity inside the Onyx AI platform.
Usage analytics, query logs, and feedback tracking across every team.
Related framework references (5)
Onyx claims fine-grained language-model provider access controls and per-team model approvals inside Onyx, which partially maps to unapproved AI control.
Onyx provides fine-grained access control for language model providers, allowing administrators to control **who** can use specific models and **which agents** can use them.
Related framework references (5)
Onyx claims self-hosted deployment, source-permission mirroring, and ACL sync to keep AI access aligned to existing data permissions.
Strict permission controls and your data never leaves your network.
Related framework references (5)
Onyx claims permission-aware connectors, document-level permissions, SCIM/IdP integration, and ACL sync for users accessing connected enterprise knowledge.
Every query respects who can see what.
Related framework references (5)
Onyx provides application programming interfaces (APIs), Model Context Protocol (MCP), connectors, and custom agents for building generative AI workflows, but does not publicly claim independent large language model (LLM) application security testing.
Full REST API, an MCP server, and a connector framework for custom data sources.
Related framework references (5)
Onyx claims query history and usage analytics for messages and application programming interface (API)-key activity inside its agent/chat platform.
On the Query History page, you can see a log of all messages sent to Onyx.
Related framework references (5)
Onyx claims controlled Model Context Protocol (MCP) actions for AI agents and admin selection of available tools, partially mapping to agent-to-tool security rather than broad agent-to-agent security.
Model Context Protocol (MCP) enables AI Agents to invoke tools and services in a controlled manner.
Related framework references (5)
Onyx claims application programming interface (API) keys exist as distinct users so administrators can trace activity and manage permissions for programmatic access.
API Keys exist as distinct users in Onyx, allowing you to trace activity and manage permissions at the key level.
Related framework references (5)
Onyx claims large language model (LLM) rate limits and throttling settings that can be applied globally, by user, or by user group.
Rate limits can be applied globally, by User, or by User Group.
Related framework references (5)
Onyx publishes a Business plan price at $20 per user per month and an Enterprise plan with flexible pricing and deployment options.
per user / month
Related framework references (2)
Onyx positions itself as a approved enterprise AI platform alternative to ChatGPT Enterprise, Microsoft Copilot, Gemini, and Glean rather than a third-party AI security monitoring layer.
Why choose Onyx over ChatGPT, Microsoft Copilot, Google Gemini, or Glean?
Related framework references (5)