onionwright · security

What leaves your machine, and what doesn’t.

Most of what a security review worries about — where the data goes, who can read it, what is retained — has the same answer here, and it is not a policy promise. The browser runs where you run it. The session never transits us, because the code that touches it never runs on our side. We verify a licence and count hours; we do not receive the work.

The data flow

Stays on your machine

Never sent to us:

  • The pages a session visits — URLs, page content, anything rendered
  • Credentials, cookies and session tokens — the browser holds them locally, the same as any browser on your machine
  • Form data, uploads, and everything the automation types or reads
  • The persona for each account — derived locally from a seed you hold, not stored by us

Leaves your machine

The only two things that do:

  • The licence check — a signed request that confirms the account holds a valid licence, so the binary will run
  • Metered browser-hours — how long a session ran, to bill usage at the hourly rate; time, not actions

The split is architectural, not a setting. There is no mode where the session contents route through us — the browser is a binary you launch, not a service we host.

What a security review asks

Does our session data pass through your servers?

No. The browser and the humanized-input layer run on your machine (or, for a private deployment, inside your own network). The pages visited, the credentials used, the cookies, the form data — none of it transits us, because the code that touches it never runs on our infrastructure. The only outbound call is the licence check.

What does the licence check actually send?

Enough to confirm a valid licence and count browser-hours: a signed request tied to the account's key, and the usage time to bill against the ConnectOnion balance. It does not carry the URLs you visited, the data you entered, or the credentials you used. We verify the licence, not the work.

Can it run fully inside our own infrastructure?

Yes. A private deployment runs the binary and the input layer on your machines, under your network, billed against your own account. The licence check is the one call that leaves your perimeter, and it can be scoped and reviewed. This is the enterprise deployment path.

Do you have a SOC 2 report or ISO 27001 certification?

Not today, and we will not imply otherwise. What we offer instead is an architecture where the sensitive data never reaches us to begin with — the session runs on your side of the line, so there is no store of your page data or credentials on our side to certify. For a regulated deployment we will work through your questionnaire directly rather than point at a report we do not have.

Who is authorised to use this, and for what?

It is a tool for authorised automation: testing, accounts you own, and work you have permission to do — the same footing as a VPN or a privacy browser. We do not build platform-specific bypass modules and we do not help evade a site's security for accounts you do not control. If the use is authorised, the tool removes the automation tells that flag legitimate work; if it is not, this is the wrong product.

For a regulated deployment

If you have a questionnaire, a data-processing agreement, or a requirement that everything run inside your own network, that is the enterprise path. We would rather answer your specific controls directly than hand you a brochure — tell us what you need to review and we will work through it.

Start a conversation