Trust Center

Security, privacy, and compliance at Orquesta. Transparency about how we protect your data.

Compliance status

SOC 2 Type IICertified

Annual third-party audit covering security, availability, and confidentiality trust service criteria.

GDPRCompliant

Full EU data protection compliance. Data Processing Agreement (DPA) available upon request.

CCPA / CPRACompliant

California consumer privacy rights. Data deletion and opt-out mechanisms in place.

HIPAAReady

Business Associate Agreement (BAA) available. PHI handling procedures and encryption in place.

OWASP Top 10Compliant

Application security tested against all OWASP Top 10 vulnerability categories.

EncryptionAES-256 / TLS 1.3

Data encrypted at rest (AES-256-GCM) and in transit (TLS 1.3). Keys managed via cloud KMS.

Security measures

Penetration Testing

Annual third-party penetration tests conducted by independent security firms. Summary available under NDA.

Vulnerability Scanning

Automated CVE scanning on every build via Snyk and Dependabot. SAST tooling integrated into CI/CD.

Secret Detection

Pre-commit hooks and CI checks prevent accidental secret leakage. No secrets stored in plain text.

Employee Security

Background checks for all employees. Mandatory security training. Least-privilege access with hardware keys.

Incident Response

Documented IR plan with 1-hour acknowledgment for P1 incidents. Postmortem published within 72 hours.

Infrastructure

Hosted on AWS and GCP with multi-AZ redundancy. Network isolation, WAF, and DDoS protection enabled.

Data protection

Encryption

  • AES-256-GCM encryption at rest for all stored data
  • TLS 1.3 for all data in transit
  • Key management via AWS KMS / GCP Cloud KMS
  • Credentials encrypted with dedicated master key
  • Database-level encryption enabled

Data residency & retention

  • Data residency options: US, EU, LATAM, APAC
  • Your code stays on YOUR machine (agent architecture)
  • Configurable data retention policies
  • Automated daily backups with 30-day retention
  • Secure data deletion on account termination

Sub-processors

Third-party services that process data on behalf of Orquesta. All sub-processors have been evaluated for security posture and have Data Processing Agreements in place.

ServicePurposeLocation
SupabaseDatabase, authentication, and real-time subscriptionsUS (AWS)
VercelBackup hosting and edge functionsUS (AWS)
Google Cloud PlatformPrimary hosting (Compute Engine)US Central (Iowa)
StripePayment processingUS
ResendTransactional and CRM email deliveryUS (AWS)
AnthropicAI model provider (Claude) for Batuta agent modeUS
OpenAIAI model provider (GPT) for Auto/Batuta modesUS
DigitalOceanCustomer VM provisioning (Cloud VMs feature)Various

Documents & agreements

Security Whitepaper

Comprehensive overview of our security architecture, controls, and practices.

SOC 2 Type II Report

Latest audit report covering security, availability, and confidentiality. Available under NDA.

Data Processing Agreement (DPA)

Standard DPA for GDPR compliance. Pre-signed template available.

Business Associate Agreement (BAA)

For healthcare customers handling PHI. Required for HIPAA compliance.

Privacy Policy

How we collect, use, and protect your personal information.

Terms of Service

Terms governing use of the Orquesta platform and services.

Responsible disclosure

We take security vulnerabilities seriously. If you discover a security issue in Orquesta, please report it responsibly. We commit to acknowledging reports within 24 hours and providing a fix timeline within 72 hours.

How to report

  • Email security@orquesta.live with a detailed description of the vulnerability
  • Include steps to reproduce, affected endpoints, and potential impact
  • Allow up to 90 days for remediation before public disclosure
  • We will credit researchers who report valid vulnerabilities (unless anonymity is preferred)

Questions about security?

Our team is happy to walk through our security practices, provide compliance documents, or answer your security questionnaire.