OneReach.ai logo
Agents Orchestration Frameworks · Workflow Automation

OneReach.ai

OneReach.ai's GSX is an enterprise platform for building, running and governing AI agents at scale. It runs in a single-tenant AWS environment, prices by capacity rather than seats, and sells only through contract.

Active GDPR compliant Enterprise API available 18+ Verified by Guidaio
Overview

What is OneReach.ai?

OneReach.ai is a US company based in Denver and Berkeley that sells a single product: Generative Studio X, usually shortened to GSX. The company describes it as an agentic orchestration platform, and its commercial argument is narrow and consistent. Building one AI agent has become easy; connecting thousands of them under governance has not.

GSX sits above an organisation's existing stack rather than replacing it, and OneReach.ai insists it is platform-agnostic and model-agnostic. Five named building blocks carry the architecture: a Communication Fabric for unified session management, a Contextual Memory System that carries state across interactions, a Cognitive Orchestration Engine that manages models and routes work by complexity, cost and latency, Intelligent Digital Workers for multi-agent systems, and a Human-in-the-Loop layer for supervision.

Everything runs inside a Private Dedicated Environment, a single-tenant deployment on AWS isolated at the network, compute, storage and data layers. The customer chooses between an environment managed by OneReach.ai and one deployed into their own AWS account, which the vendor presents as the standard path where data sovereignty is required.

The platform is broad. Its capability pages describe a shared library of more than 1,200 steps, prebuilt integration toolkits for over 60 enterprise systems, 47 predefined analytics metrics, a no-code drag-and-drop builder alongside a full SDK, PII redaction and masking, and role-based access control with thirteen supported identity methods.

The company claims more than 150 employees, 1.5 billion agent interactions a year and over 10,000 deployed agents, and traces its research lineage to DARPA. It says it has been named in more than 160 Gartner reports. Four case studies support the pitch, one of them named, the telecom operator Lebara, the other three anonymised behind figures such as 80 million dollars of added annual profit for a US retailer.

Access is entirely commercial. There is no signup, no free tier and no published price: the environment is sized with the vendor before any contract, and the model bills capacity rather than seats, agents or tokens consumed.

What it does

  • Build multimodal AI agents with a drag-and-drop interface or with code
  • Orchestrate multi-agent systems across channels, workflows and environments
  • Register every agent before it acts and enforce policy at runtime
  • Connect agents to more than 60 enterprise systems through prebuilt toolkits
  • Ground agents in company knowledge using vector and graph retrieval
  • Keep humans in the loop for supervision, disambiguation and live handover
  • Measure conversations against 47 predefined out-of-the-box metrics
Audience

When to use OneReach.ai / When not to

A quick filter to help you decide if OneReach.ai is the right fit.

When to use OneReach.ai

  • Enterprises already running several isolated AI agents and hitting agent sprawl
  • Regulated organisations in government, finance and healthcare that need single-tenant isolation
  • IT and platform teams required to deploy inside their own AWS account for data sovereignty
  • Companies that want to own the source code, orchestration logic and configurations they build
  • Cross-departmental AI programmes needing audit lineage and policy enforcement at runtime

When not to use OneReach.ai

  • Individuals and small businesses: there is no self-service signup and no published price
  • Anyone wanting to test before talking to sales, since no free plan and no free trial exist
  • Teams needing a single chatbot or one standalone assistant, for which the platform is oversized
  • Developers expecting public API documentation: the SDK is only documented under contract
  • Mobile-first users, as there is no iOS or Android application and no browser extension
Get started

How to use OneReach.ai

A typical end-to-end flow, from setup to results.

  1. Read the platform overview and the Trust Center to check the architecture against your requirements
  2. Request a technical demo or get in touch through the contact form, as there is no self-service signup
  3. Expect a reply from the OneReach.ai team within one business day
  4. Optionally submit one of your own use cases, which the vendor offers to build as a working agent system
  5. Size the Private Dedicated Environment with the vendor, based on concurrency and processing capacity
  6. Choose a service model: fully managed, pure infrastructure, or a combination of both
  7. Choose the hosting mode: an AWS environment managed by OneReach.ai, or your own AWS account
  8. Sign the contract, then have the environment provisioned and connected to your identity provider
  9. Build agents in the drag-and-drop studio or with the SDK, reusing the prebuilt solutions library
  10. Define governance policies, autonomy limits and RBAC roles, then monitor agents through analytics and audit logs
Quick read

Pros & Cons

Pros

  • Single-tenant isolation by default, against the multi-tenant model of most competing platforms
  • Deployment into the customer's own AWS account is offered, which matters for data sovereignty
  • The customer owns and can export the source code, orchestration logic and configurations they build
  • No seat licensing and no agent caps: users and solutions are unlimited
  • Model tokens, compute, telco and storage are passed through at cost, and you may bring your own API keys
  • Three independent certifications, SOC 2 Type II, UK Cyber Essentials and HITRUST, with a dedicated Trust Center
  • 24/7 support is standard across all three service models

Cons

  • No published price at all: the pricing sheet sits behind a form and everything else goes through a quote
  • No self-service signup, no free plan and no free trial
  • The published terms and conditions govern OneReach's legacy telecom services, and never name GSX
  • The privacy section of those terms has no GDPR mechanics: no rights, no legal basis, no retention period
  • At the Trust Center, both the Privacy Policy and the DPA links resolve to a placeholder anchor
  • No public API or product documentation: the SDK is only documented once you are a customer
  • AWS hosting is advertised but no region or country is ever named, and no subprocessor list is published
Pricing

Pricing & Plans

There is no free plan and no free trial, and OneReach.ai publishes no price for GSX. Pricing is based on the size of the Private Dedicated Environment, measured by concurrency and processing capacity rather than by seats, agents or tokens consumed, with rates that flatten as usage grows. Within that environment, AI model tokens, cloud compute, telco and storage are passed through at cost with no markup, and customers may use their own API keys for third-party services. A figure can only be obtained by downloading the pricing sheet through a form or by requesting a cost consultation.

Single platform scope with no named tiers
  • every deployment includes the full platform
  • with no capability gates and no modules sold separately
Plan 3
  • Fully managed service model
  • in which OneReach.ai designs
  • builds and runs the solutions
Plan 4
  • Pure infrastructure service model
  • in which the customer builds and OneReach.ai provides the platform
Plan 5
  • Combined service model mixing managed delivery and self-build
  • with 24/7 support standard on all three
Special offers — No promotional pricing, discount or coupon of any kind is offered · An Academic Fellowship programme is open to researchers, and a proof of concept built on a use case you supply is offered before contract
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how OneReach.ai handles your data.

GDPR overview

OneReach.ai claims GDPR compliance explicitly. Its Trust Center lists GDPR alongside HIPAA, CCPA, LGPD, the EU AI Act, FedRAMP, SOX and SHIELD under regulatory compliance support, and the Data Privacy & Protection page states that GSX complies with a range of regulations including GDPR. The Data Privacy Framework appears among its listed frameworks, and a Data Processing Agreement is named among its legal documents. The published documents do not follow through. The only legal text on the site is a terms page whose privacy section is an older US-style statement: it never mentions the GDPR, and describes no data subject rights, no legal basis and no retention period. No Article 27 EU representative is designated, no EU address is given, and no dedicated privacy contact exists. The DPA link resolves to a placeholder.

Who owns the data?

The terms state that all intellectual property in the platform, its materials and its content belongs to OneReach, and that the agreement grants access rather than any licence to the source code. What the customer builds is treated separately: OneReach.ai states that the source code, orchestration logic and configurations are the customer's, that they remain exportable, and that they survive the end of the contract, which is why a share of clients book the platform as a capital asset. For the website itself, the privacy section declares OneReach the sole owner of information collected on onereach.ai. Interaction data stays under the customer's authority for storage, retention and export.

Reuse rights

Platform materials and content cannot be reused freely: the terms forbid copying, reproducing, modifying, publishing, transmitting or distributing them without prior written permission, and describe the agreement as an access licence conveying no rights over the software. What the customer creates is the opposite case, since configurations are exportable and the intellectual property stays with the customer, so those assets can be reused without asking. On interaction data, OneReach.ai says it may be used to refine AI performance, but only within customer-configured retention policies, model-provider data handling agreements and internal governance controls, and the organisation decides whether that data is stored at all.

Data retention & training

Retention summary
Retention is configurable rather than fixed. Policies are set at the Private Dedicated Environment level, giving each customer control over how long data is stored, and OneReach.ai states that once the defined retention period has elapsed the data can be permanently deleted. Historical logs and previous configurations are preserved according to those same customer policies. The organisation also keeps authority over whether interaction data is stored at all, how long it is kept, and who may export or audit it. No default duration is published anywhere: no number of days or months, no floor and no ceiling. For the website itself, the terms give no retention period either, and offer correction or deletion of personal data by emailing support.
Trains on customer data
Configurable
Training opt-out available
Yes
DPA available
Yes

Hosting summary

GSX is hosted on AWS in a Private Dedicated Environment, a single-tenant deployment provisioned for one customer and isolated at the network, compute, storage and data layers. It is not a shared instance with tenant-level segmentation. Two arrangements are offered: an environment hosted and managed by OneReach.ai inside a dedicated AWS account, or one deployed directly into the customer's own AWS account, which the vendor presents as the standard path where data sovereignty is required. A typical environment uses a dedicated VPC with private subnets, containerised runtime services, isolated data stores, encrypted object storage, IAM roles scoped to least privilege, and optional VPN or Direct Connect links into the customer network. Data is encrypted with AES-256 at rest and TLS 1.2 or above in transit, with network segmentation and security groups following AWS practice. One element is missing: no hosting region and no country is ever named. The site repeats that deployment is on AWS and that private deployment answers sovereignty requirements, but leaves the actual jurisdiction to be settled in the contract. No subprocessor list is published either.

Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting OneReach.ai.

  • The terms and conditions you would be agreeing to describe a telecom product, not GSX, which is an unusual gap for a platform sold to regulated industries
  • GDPR compliance is claimed on the Trust Center but nothing published implements it: no data subject rights, no legal basis, no retention period, no EU representative
  • The privacy policy and the DPA are named as documents but their links lead to a placeholder, so neither can be read before you commit
  • Delegating decisions to autonomous agents concentrates operational risk: the governance controls exist, but they only work if someone actually defines the policies and reads the audit trails
  • Interaction data may be used to refine AI performance and the limits are the ones you configure, so a default left unexamined becomes a decision made by inaction
  • The headline figures, 150+ employees, 1.5 billion interactions a year, 10,000 agents and 160+ Gartner reports, are the vendor's own claims and cannot be verified from outside
  • Three of the four case studies are anonymised, so their reported gains cannot be checked against a named customer
Setup

Setup & Integrations

Technical difficulty

There is no self-service setup: the environment is sized with the vendor before any contract. After that, difficulty depends on the service model chosen. Fully managed means OneReach.ai designs, builds and runs the solutions, while pure infrastructure puts the build work on your team. Agent construction itself is accessible, with a drag-and-drop studio for non-developers and an SDK for developers, and prebuilt toolkits reduce integration effort. Deploying into your own AWS account demands real cloud and network skills, including VPC, IAM and Direct Connect. Governance policies, autonomy limits and RBAC roles must be defined whichever route you take.

Deployment

Web appAPI

Integrations

Salesforce Oracle Monday.com Zendesk Pipedrive HubSpot ServiceNow Workday PeopleSoft UKG Dimensions Gusto Office 365 Tableau Power Apps Snowflake Genesys Okta Active Directory Azure AD JumpCloud AWS SSO Duo SSO Idaptive LastPass OneLogin RSA SecurID SecureAuth Symantec VIP Access AWS

Supported languages

EnglishChineseArabicSpanishTurkishCzechSlovakRussianUkrainianLatvianRomanianItalianFrenchGerman
Company

Behind OneReach.ai

Company name
OneReach Inc
Founded
03/08/2018
Country of origin
🇺🇸 United States
Headquarters
4055 Tejon St, Denver, CO 80211, United States
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇮🇪 Ireland
Support contact

Fundraising

Private equity investment from LoneTree Capital, announced on 26 January 2022, amount undisclosed. It is the company's first and only known funding round, the business having been self-funded before that, and the stated purpose was global market expansion, application support and future product development. This comes from an off-site announcement: onereach.ai itself publishes no funding information.

Social

Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

How much does OneReach.ai GSX cost?
No price is published. Pricing is based on the size of your Private Dedicated Environment, measured by concurrency and processing capacity, not by seats, agents or tokens consumed. You obtain a figure by downloading the pricing sheet through a form or by requesting a cost consultation, and the environment is sized with the vendor before any contract.
Is there a free trial or a free plan?
Neither, and there is no self-service signup. The entry point is a contact form or a demo request. OneReach.ai instead offers to build a working agent system on a use case you bring, which serves as the proof of concept in place of a trial.
Who owns what I build on the platform?
You do. OneReach.ai states that the source code, orchestration logic and configurations are yours, that all system configurations are exportable, and that they remain yours after the contract ends. A significant share of customers classify the platform as a capital asset for that reason.
Where is my data hosted?
In a single-tenant Private Dedicated Environment on AWS, isolated at the network, compute, storage and data layers. It can be managed by OneReach.ai in a dedicated AWS account, or deployed into your own AWS account. No hosting region or country is ever named on the site.
Which certifications and compliance frameworks are claimed?
SOC 2 Type II, UK Cyber Essentials and HITRUST are listed as independent certifications. GDPR, HIPAA, CCPA, LGPD, the EU AI Act, FedRAMP, SOX and SHIELD are listed as supported regulatory frameworks, and NIST AI RMF, NIST CSF 2.0 and NIST 800-171 as risk frameworks.
Is my data used to train AI models?
OneReach.ai states that interaction data may be used to refine AI performance, but subject to customer-configured retention policies, model-provider data handling agreements and internal governance controls. The organisation keeps authority over whether interaction data is stored at all, how long it is retained, and export and audit access.
Is there an API and public documentation?
The platform ships a full SDK and an open architecture that lets you build APIs for internal or legacy systems, alongside prebuilt toolkits for more than 60 enterprise systems. However, no public API or product documentation is reachable without a contract.
Which languages does the platform support?
Fourteen language families are listed as in production, including English, Chinese, Arabic, Spanish, French, German, Italian, Russian, Ukrainian, Turkish, Czech, Slovak, Latvian and Romanian. A much longer secondary list of over a hundred additional languages is also published.
Is there a mobile application?
No. GSX is a web platform with an SDK. Its multimodality refers to voice, text and visual channels within a single conversation, not to native iOS or Android applications, and no app store listing exists.
What is the minimum age to use the service?
The published terms require users to be at least 18 years old, or the applicable state age of majority. Note that those terms govern OneReach's legacy telecommunication services rather than the GSX platform itself.
Conclusion

Should you pick OneReach.ai?

OneReach.ai is a genuinely established vendor rather than a promise. The company was trading well before the current agentic wave, publishes a Denver address and a legal entity, holds three independent certifications, and runs a Trust Center detailed enough to describe its VPC layout and encryption standards. GSX is a real platform, and the depth of its integration and governance work shows in the documentation.

The reservations are not about the product but about what the company publishes around it. The only terms and conditions on the site govern OneReach's older telecommunication business, with toll-free numbers, short codes and per-minute billing, and never mention GSX at all. Their privacy section is an ageing US text with no GDPR mechanics, while the Trust Center simultaneously claims GDPR compliance. Both the privacy policy and the DPA links there lead nowhere. There is no subprocessor list, no EU representative and no named hosting region.

Pricing is another wall, though a legitimate one. Nothing is published and nothing can be evaluated without engaging a salesperson and sizing an environment. That is normal for infrastructure sold this way, but it does put the platform out of reach for anyone who cannot commit to a procurement cycle.

Who it is for: large organisations running AI agents across several departments, especially in regulated sectors, that need single-tenant isolation, runtime policy enforcement and audit lineage, and that value owning the code they build. What to check first: ask for the DPA and a compliant privacy policy in writing, ask which AWS region will host your environment, and ask for contractual terms that actually name GSX. On the evidence currently published, none of those three answers is on the website.