A role sets the boundary.
Roles define what a person can read and do. Questions and actions use the same permission checks as the rest of the service. Asking does not grant more access.
Your company’s record connects commitments, decisions and actions. That should make the business more accountable without making its information available to everyone.
Access follows a person’s role and the company they belong to. Private information has a separate boundary.
Roles define what a person can read and do. Questions and actions use the same permission checks as the rest of the service. Asking does not grant more access.
Your private conversations and personal notes are not visible to company administrators. An explicit contribution is required before private information enters the company record.
Every record belongs to one company, and two separate boundaries keep companies apart: one in the application and one in the database. Facts extracted from your sources are protected the same way as the sources.
Connection credentials stay out of answers, prompts and API responses. Reading a record does not give a person or an agent permission to act on it.
Connected documents and messages are temporary by default. The lasting record keeps facts and references. Other information has its own reason to stay.
What is collectedAuthorized documents, messages and business records from the tools you connect.
What staysExtracted facts, summaries and source references. Raw documents and messages are temporary by default; authorized evidence can be fetched again.
What is collectedIdentity, membership, roles, preferences and connection settings needed to provide the service.
What staysWhat is needed for sign-in, administration and access, until the account or company is deleted.
What is collectedQuestions, responses and the conversation context needed for follow-up work.
What staysConversation history until you delete it, or until the retention period your company has set.
What is collectedWho acted, what was requested, which rules applied and the recorded decision or outcome.
What staysAudit history and receipts. These are kept longer than source content because they are the company’s record of what happened.
Temporary originals do not mean nothing is stored. Extracted facts can still contain sensitive information.
Read the privacy policyPeople and agents face the company’s checks before an important action goes out. If a required check cannot complete, the action is held.
Policies & approvalsCheck authority and company rules. Hold when a required answer is missing.
Keep who decided, who approved and which rules applied. Corrections add to the history.
Checks can hold the actions you send through them. Activity only learned about afterward can be recorded, but cannot be stopped.
Where data rests and where software runs are different requirements. Agree both before connecting the business.
The default operated service uses Google Cloud in US regions. Dedicated hosting and other data-region requirements are scoped with the team.
A scoped engagement can keep data at rest in your environment, with private connectivity to the service. Processing still takes place in the service’s environment.
Accounts · Sessions · Billing · Web interface
Managed hosting, or dedicated hosting and customer-owned storage by agreement
No SOC 2 attestation or ISO 27001 certification is currently claimed. Start with the requirements and the evidence available to assess them.
Sources, permissions, retention and deletion requirements.
Hosting region, encryption, key custody and connectivity.
Subprocessors, AI data flows, processing terms and training restrictions.
Available assessment evidence and incident-response arrangements.
A verifiable record helps a customer, auditor, insurer or board check what was recorded. It does not certify compliance or prove the action was correct.
Request a security reviewPractical answers for the people reviewing the service.
Members can use Google sign-in, passwords or passkeys, and add multi-factor authentication. Active sessions can be reviewed and revoked. Company roles determine what each member can read and do.
In transit, always. At rest, with the cloud provider’s encryption, and credentials for connected tools are encrypted separately for each company. Ask about key custody and customer-managed keys during your review.
No. The record grows from connected evidence and recorded outcomes, not from training models on your conversations. External AI providers process the content of a request to answer it. Their data-use, retention and no-training terms are part of your security review.
Yes. Request the current subprocessor register during your security review. Confirm which providers receive which information and the processing terms that apply to your deployment.
No. Disabling a connection stops new collection, but does not automatically erase extracted facts or required history. Retention, privacy and deletion processes govern those records separately.
Read the privacy policy
Full customer-hosted and air-gapped installations are not currently offered. Dedicated hosting and customer-owned storage are scoped engagements. Customer-owned storage changes where data rests; processing stays in the service’s environment, and accounts, sessions, billing and the web interface remain centrally hosted in US regions.
No SOC 2 attestation or ISO 27001 certification is currently claimed. Framework mappings and verifiable records can support a review, but do not replace independent assurance. Ask for the current assessment status and available evidence.
Explore compliance frameworks
Verification checks the integrity of a recorded event or shared packet. It does not establish that the underlying action was correct, that every event was captured or that the company is compliant.
Receipts & verification
You can export your company’s record and then request deletion. The export, the deletion process and its timing are set out in the agreement and the privacy policy, and private member data is deleted with the member.
Read the privacy policy
Send the affected feature and steps to reproduce the issue. Keep credentials and private customer content out of your report. Reports are acknowledged; good-faith research that follows this guidance will not be met with legal action.
security@orcinta.com