Oway
Request a DemoLog In
Security

Built for the systems that run the physical world.

Your operation’s data stays yours. Oway protects every node, connection and action with enterprise-grade security and controls.

Start FreeTalk to Our Sales Team

Log in now and access Oway OS and Juno for free.

Enterprise-grade protection

Security is built into the protocol.

Customer-Owned Nodes

Every IOI node belongs to the company that runs it. Your operational data is never pooled with another customer’s, and you decide what leaves your node.

Permission Before Every Connection

A node connects to a partner, agent or machine only with the owner’s explicit permission. Every grant has a scope, and every grant can be revoked.

Your Data Serves You

Models that optimize your node run on your data for your operation. Nothing on your node is used to serve another company.

Scoped Agent Access

Juno and AI agents reach a node through MCP with the scopes you set: read, propose or act. Sensitive actions wait for a person to approve them.

Safe Plant Connectivity

Connections to plant and machine systems are segmented from corporate networks, run with least privilege and respect the safety systems already in place.

Full Audit Trail

Every query, approval and action is logged with who took it, when, and with what data.

Controls

Enterprise-grade security and controls.

The controls behind every node, connection and action on Oway.

Encryption

Data is encrypted in transit and at rest.

Identity and access

Single sign-on, role-based access and least-privilege permissions for every user, agent and integration.

Enterprise hosting

Enterprise data lakes are hosted on Microsoft Azure, with data kept in the United States.

Testing

Regular penetration testing, vulnerability management and code review.

Partner vetting

Carriers and partners are checked for operating authority, insurance and identity before they receive work.

Fraud controls

Every order, document and payment instruction is screened at intake.

Our approach

Security is fundamental to everything we do.

Oway connects the systems that run factories, warehouses, fleets and machines. A connection like that is only useful if it is trusted. We design every part of the platform so the company that owns the operation stays in control of it: what is connected, who can see it, and what anyone, person or machine, is allowed to do.

This website

Hardened against modern attacks.

The same care we put into the platform protects every page and form on this site.

Strict Content Security Policy

Every page runs with no inline scripts, and only our own code can execute. Analytics scripts are allowed only after you consent.

Subresource Integrity

Each script and stylesheet carries a cryptographic hash, so the browser refuses any file that has been altered.

Encrypted by default

TLS 1.2 or newer everywhere, with HSTS preload so browsers never connect over plain HTTP.

Web application firewall

AWS WAF screens traffic with managed rule sets, IP reputation lists and per-visitor rate limits.

Private form endpoints

Forms post to signed, same-origin endpoints behind the firewall. The functions behind them cannot be reached directly.

Prompt-injection defenses

Submissions are normalized, stripped of hidden characters, checked for injection patterns and labeled as untrusted before they reach a person or an AI system. Juno treats retrieved content as data, never as instructions, and agent actions stay inside scoped permissions with approvals.

Isolation headers

Frame, opener, resource and permissions policies stop clickjacking, cross-site leaks and access to your camera, microphone or location.

Privacy by default

No analytics or marketing cookies run until you choose, and the Global Privacy Control signal is honored automatically.

Responsible disclosure

Found a vulnerability? Tell us.

Email help@oway.io with steps to reproduce. We acknowledge reports within three business days and keep you updated until a fix ships. Test only against your own accounts, never access or change other people’s data, and give us reasonable time to fix an issue before sharing it. We will not pursue legal action for good-faith research that follows these rules.

Questions

Security and data privacy.

How does Oway define customer data?

Customer data is everything that flows into or out of your IOI node: records from your systems, machine and sensor data, documents, questions you ask and the answers and actions that follow.

Where is my data hosted and processed?

Enterprise data lakes are hosted on Microsoft Azure in the United States. Ask our team about specific regions and deployment options.

Who can see my node?

Only the people, agents and partners you grant access to, within the scopes you set. Oway staff access is limited to support you authorize, and it is logged.

How do AI agents get access?

Through MCP, with scoped permissions per agent. Agents can read, propose or act only where you allow it, and sensitive actions require approval.

How are carriers and partners vetted?

Every carrier is checked for active operating authority, insurance and identity before receiving work, and is monitored while active on the network.

How do I report a vulnerability?

Email help@oway.io with the details. We review every report and respond to valid findings.

A painting of rail yards lit in red at dusk.

Optimize your industrial systems with Oway.

Start free with Juno and Oway OS today, or set up IOI for your enterprise with your data private from day one.

Start FreeTalk to Our Sales Team

Log in now and access Oway OS and Juno for free.