Skip to content
Ohalo is now DataXray.What changed
Security and trust

DataXray runs inside your boundary

Your files are read where they are stored and never leave your environment, including in air-gapped enclaves with no external connectivity.

  • No external connectivity
  • Runs in containers on RHEL
  • Models run on your infrastructure
  • Read-only by default
Enterprise and government

The certifications and standards your vendor security review will check

  • DoW ATOAuthority to Operate on three networks in the U.S. Department of War
  • SOC 2 Type 2Ohalo Limited, annual audit
  • ISO 27001Information security management
  • FIPSFIPS-compliant cryptography
  • STIGSTIG-compliant implementations

Deployment isolation

DataXray scans without calling out to a hosted service, so it works in environments with no external connectivity, where cloud-based classification tools cannot. It runs in the cloud, in hybrid setups, on-premises, and in air-gapped enclaves, with the same capabilities in each.

  • Nothing is installed on your endpoints or file servers. DataXray connects to each source through a least-privilege service account, read-only by default.

  • Containers run on RHEL with Podman or Docker, on physical or virtual infrastructure. The images are pulled once, and the deployment then runs with zero external connectivity. We sign each release image with Sigstore Cosign, so you can verify it has not been tampered with, even inside an air-gapped enclave.

  • From install to first scan in hours, not weeks. There are no agents to roll out and no infrastructure to build, just containers and service accounts.

  • Classification and language models can run entirely inside your environment, with no outside AI service, so your files are never sent out for analysis.

  • Users authenticate through your identity provider, so access follows the roles you already manage.

  • 55+ native connectors, plus a universal connector for anything else, whether that's legacy, bespoke, or in-house. See all integrations.

Data handling

This is how DataXray treats your files while it reads, classifies, and logs them.

  • Your data stays in your environmentDataXray reads each file where it is stored, and the results stay inside your environment. Nothing is transmitted outside it.
  • Scanning never alters your filesDiscovery and classification never change your source files. Labeling and redaction happen only when you choose them, and each one is logged.
  • Every classification is recordedDataXray records what was found in each file, which rule or model found it, and when the file was last checked. When your classification rules change, it reclassifies the affected files, so their labels stay current.
  • Audit logs for your SIEMEach scan produces audit logs your SIEM can ingest, showing what was found and where.
  • Support diagnostics exclude your file contentsWhere support diagnostics are shared, they cover product performance, configuration, and error information, not the contents of your files. See the end user license agreement for the definitions.
Report a security vulnerability

Responsible disclosure

If you believe you have found a security vulnerability in DataXray or in our own systems, email security@dataxray.io with enough detail to reproduce the issue. We will acknowledge your report, keep you informed as we investigate, and credit you if you wish once the issue is resolved. Please do not access, modify, or exfiltrate data that is not your own while testing.

Frequently asked questions

Can DataXray run in an air-gapped environment?

Yes. It deploys into closed, air-gapped enclaves with zero external connectivity, as a container on RHEL with Podman or Docker. It is the same software that runs in cloud and hybrid deployments, and its models run inside the enclave, so your files are never sent out for analysis.

Is DataXray SOC 2 compliant?

Yes. Ohalo holds SOC 2 Type 2, covering independently audited controls for security, availability, and confidentiality, and is ISO 27001 certified.

Does DataXray use FIPS-compliant cryptography?

Yes. It uses FIPS-compliant cryptography to protect sensitive information.

Has DataXray achieved an ATO?

Yes. Authority to Operate has been achieved on three networks in the U.S. Department of War, including closed, air-gapped enclaves. An ATO is granted by the customer agency for a specific system in a specific environment. Deployments are STIG-compliant, which is typically what an accreditation package requires.

Do you have a trust portal?

Yes. Our trust portal runs on Vanta and holds our security documentation and certifications.

Can DataXray classify CUI?

Yes. It discovers and classifies Controlled Unclassified Information across unstructured sources, and applies machine-readable tags that downstream controls such as encryption, access restriction, and retention can act on.

Does our data leave our environment?

No. DataXray is deployed inside your own environment, and your data never leaves it. Its models run on your infrastructure, and it connects to your sources with read-only access by default.

Does DataXray keep copies of our files?

It keeps a searchable record of each file inside your environment, and you choose whether that record holds the full text or only what was found in it. None of it is stored anywhere else.

How long does deployment take?

Hours rather than weeks, including in air-gapped environments. DataXray is agentless and containerized, so there is nothing to install on endpoints or file servers.

Take DataXray through your security review.