Skip to content

Security that follows your data and decisions.

Keep organizational context within clear boundaries, control who can act, and preserve a record that stands up to review.

Extract intelligence without building a document archive.

Documents and messages from authorized sources are processed temporarily by default. The lasting record keeps extracted intelligence, citations, and provenance so the original evidence can be revisited.

Explore organizational memory
Your organization
Private member sourcesExplicit contribution required
Retain cited context after temporary source processing.
Source handling

Keep what gives the record meaning.

Raw source content is temporary by default. Claims retain citations and provenance so the evidence can be revisited.

Private by scope

Keep personal sources separate.

Private member-vault information enters shared intelligence only through an explicit contribution.

Authorized answers

Carry permissions into the conversation.

Retrieval and actions respect workspace access. Asking a question does not create permission to see more.

Know what we collect and why it stays.

Source processing is one part of the data lifecycle. Accounts, conversations, and action records serve different purposes and have different retention rules.

Data categoryWhat is collectedWhat is retained

Connected sources

What is collectedDocuments, messages, and business records within the authorized connection scope.

What is retainedExtracted signals, claims, summaries, source references, and provenance. Raw source content is temporary by default.

Accounts and workspaces

What is collectedWork identity, membership, roles, preferences, and connection configuration needed to operate the workspace.

What is retainedAccount and workspace records support sign-in, administration, and access controls, with their own deletion lifecycles.

Questions and conversations

What is collectedQuestions, responses, and conversation context used to answer and support follow-up work.

What is retainedConversation history remains available until explicitly deleted, unless an installation has a configured retention window.

Actions and security events

What is collectedActor, action, policy, verdict, and event metadata needed for accountability and security.

What is retainedAudit records and receipts preserve the event history. Their retention and legal obligations differ from temporary source content.

Protect the intelligence as well as the source.

Extracted facts can contain sensitive business information. Organization boundaries, permissions, and private member-vault controls continue to apply after extraction.

Treat disconnection and deletion separately.

Disabling a connection stops new collection. Removing it does not automatically erase all derived intelligence or required history. Retention, privacy, and deletion workflows govern that record.

Access should be deliberate at every layer.

Connect identity, workspace permissions, and organization boundaries throughout the product.

01
Identity

Know who has access.

Sign in with Google, a password, or a passkey, and add multi-factor authentication. Review active sessions and revoke access when a device should no longer be trusted. AI agents can be linked to the directory principal they run as, so a disabled principal is visible on the agent record.

02
Permissions

Give each role the access it needs.

Custom workspace roles define what a person can read and do. Questions and actions use the same permission checks as the rest of the workspace.

03
Isolation

Keep each organization within its boundary.

Every query is organization-scoped in the application layer, and the data model is designed for database row-level policies as a second boundary where a deployment enables them. Data moves over TLS in transit, managed database storage is encrypted at rest by the cloud provider, and sensitive credentials use encryption bound to their organization’s context.

04
Secrets

Keep credentials out of every output.

Credentials are typed as secrets. They redact themselves in logs and representations, and are kept out of API responses.

05
Audit

Record every change as it happens.

Every mutation writes an append-only audit record on the same transaction, delivered through an outbox, so the change and its record cannot drift apart.

06
Source content

Process sources without keeping them.

Raw source content is not persisted by default. Full content is fetched again on authorization and held only in an expiring processing cache while a job runs.

Important actions need authority and a record.

Put controls in the execution path, then keep the evidence of what was decided.

Resolve uncertainty before execution.

Governed actions require a verdict. If a required rule cannot be evaluated, the action is held instead of silently proceeding.

Explore agent governance

Make the history independently checkable.

Receipts form a hash-chained, append-only sequence, and the audit log is append-only. Available proofs and conformance packets let reviewers check the integrity of the recorded sequence.

Explore receipts and verification

Enforcement applies to actions routed through governance. Activity observed afterward is recorded as observed evidence, with its coverage limits intact.

Start your security review with the right questions.

Walk through your requirements with our team and confirm the controls, evidence, and deployment scope that apply.

Data handling

Connected sources, processing scope, retention, and deletion requirements.

Infrastructure and keys

Hosting region, infrastructure protections, encryption, and key custody.

AI services and subprocessors

Configured providers, data flows, processing terms, and training restrictions.

Assurance and operations

Available assessment evidence, access controls, and incident-response arrangements.

Deployment requirements

Single-tenant, bring-your-own-cloud, and on-premises deployments are available under the Sovereign package. They are delivered with our team rather than self-serve, and region, key custody, and deployment scope are agreed for each engagement.

Explore packages

What would you like to know?

Do you keep copies of our connected documents?

Connected documents and messages are processed temporarily by default, rather than retained as a permanent document archive. The lasting record contains extracted intelligence, summaries, citations, and provenance. Intelligence can still contain sensitive business information, so access controls and retention requirements apply to that record too.

What happens to connected source content?

Raw connected-source content is temporary by default. Processing retains normalized signals, claims, citations, and provenance so answers can point back to the evidence. Authorized evidence can be fetched again when needed. Retention and deletion requirements are reviewed for the deployment.

Can someone see another member’s private sources?

Private member-vault data remains separate from shared organizational intelligence. An explicit contribution is required to move information into the organization’s record. Workspace answers and actions are permission checked.

Does organizational learning train a model on our data?

Organizational learning uses context, retrieval, and recorded outcomes, rather than model training on workspace conversations. Where external AI services process requests, confirm the configured providers, data-use terms, retention, and training restrictions during your security review.

Are you SOC 2 attested or ISO 27001 certified?

We do not currently claim a SOC 2 attestation or ISO 27001 certification. Control mappings and verifiable records can support an assessment, but they do not replace independent assurance. Contact our team for the current assessment status and available evidence.

Can we choose where our data runs?

Region, key custody, and deployment requirements are agreed with our team. Single-tenant, bring-your-own-cloud, and on-premises deployments are available under the Sovereign package and are delivered with the team rather than self-serve. Confirm availability and scope before selecting a package.

Which sign-in methods are supported?

Members can sign in with Google, a password, or a passkey, and can add multi-factor authentication. Sessions are listed and can be revoked. AI agents can be linked to the directory principal they run as, so a disabled principal is visible on the agent record.

How is data encrypted?

Traffic to the hosted service travels over TLS. Managed database storage is encrypted at rest by the cloud provider as its default, and sensitive credentials are additionally encrypted with keys bound to their organization’s context. Key custody for a dedicated deployment is agreed during the deployment review.

Do you publish a subprocessor list?

A register of subprocessors and the customer data each one receives is available on request. Ask for it during your security review together with the configured AI providers and their data-use terms.

How do deletion and audit history work together?

Deletion and privacy workflows remove or restrict eligible content while preserving the integrity of required audit and receipt history. Retention policies and legal holds affect what can be removed. Confirm the applicable data classes and obligations during your review.

Does receipt verification prove an action was safe?

Verification checks the integrity of the recorded history. It does not prove that a decision was correct or establish regulatory compliance. Actions checked before execution are distinguished from activity observed after it happened.

Report a security concern.

Share the affected feature and the steps needed to reproduce the issue. Please keep credentials and private customer content out of your report. Reports are acknowledged, and good-faith research that follows this guidance will not be met with legal action.

security@orcinta.com

Put your requirements on the table.

Review data handling, access, and deployment with our team.

We do not currently use analytics or advertising cookies. Cookie policy · Privacy policy