Security

Written as practices,
not badges

This page says what Orrin is being built to do and what is true today. No certification is claimed. Each practice is marked Planned until it is live and verified, and then it is marked Live with the date.

No customer data is processed yetSOC 2 planned, not held
  1. 01

    Tenant isolation

    Each vendor workspace gets its own search index, conversation logs, audit log and credentials. Nothing is shared across workspaces at any layer.

    Planned
  2. 02

    Token model

    The vendor’s backend mints a signed token per end user that lives between five and fifteen minutes and carries the user id, company id, role and scopes. The widget sends it with every request. Orrin never holds a shared service account for end user actions.

    Planned
  3. 03

    Confirmation model

    Every Write action shows a preview and waits for the user’s Confirm. Sensitive actions require a typed word. The confirmation is bound to the exact action, inputs, user and tenant, and permission is checked again immediately before execution.

    Planned
  4. 04

    Audit log

    User, company, tool, parameters, the preview shown, the confirmation, the API response and the timestamp are written for every action and kept in the vendor’s isolated log.

    Planned
  5. 05

    Encryption in transit and at rest

    All traffic uses TLS. Stored documents, indexes and logs are encrypted at rest by the hosting providers named below.

    Planned
  6. 06

    Retention and deletion

    Deleting a document removes its chunks from the index within minutes. Conversation and audit logs follow a retention period set per workspace.

    Planned
  7. 07

    Prompt injection defenses

    Retrieved documents and API responses are treated as data, never as instructions. Tools come only from the vendor’s allowlist. Every write still requires the user’s confirmation.

    Planned
  8. 08

    No training on customer data

    Customer documents and conversations are never used to train models.

    Planned
  9. 09

    Subprocessors

    This website is hosted on Vercel. The runtime providers for models, search and storage will be named here before any customer data is processed, and every workspace will be told before a subprocessor changes.

    In use
  10. 10

    Incident contact

    Security reports go to the security mailbox published on this page. Affected workspaces are told within seventy two hours of a confirmed incident.

    Planned
  11. 11

    SOC 2

    A SOC 2 audit is planned. Orrin does not hold SOC 2 or any other certification today.

    Planned

Security reports

The security mailbox is published here before the first production workspace opens. Until then, use the Security review topic on the access form.

Security overview

The same practices, laid out as one document for procurement and review. It says exactly what this page says, and nothing this page does not.

Data

Your data
stays yours

Customer data is never used to train models. Every workspace can export or delete its documentation, conversation logs and audit log. A data processing addendum is available on request once the first production workspace opens.