Skip to main content
๐ŸšจEarly AccessOrvoq is currently in early access. Expect occasional rough edges as we test, refine, and prepare for launch.
Security

Built to survive a real security review.

Orvoq is designed for enterprise use from the ground up โ€” every screen you'd expect an IT or security team to ask about already exists as a real control, not a promise on a slide.

โœ“
SOC 2 Type II
Not yet certified โ€” controls aligned to Trust Services Criteria
๐Ÿ”’
AES-256 at rest
TLS 1.2+ in transit
๐ŸŒ
Regional data residency
US and EU available
๐Ÿ“‹
GDPR & CCPA
Compliant data handling
โš™

Layered access control

Roles at the Organization, Workspace, and Session level โ€” the most restrictive applicable role always governs. A contractor sees the one session they're on, never your whole company's conversations.

๐Ÿ“œ

Full audit trail

Every state-changing action โ€” a decision, a permission change, an agent's tool call โ€” is traceable to an actor and a timestamp. Session Replay reconstructs exactly what happened, on demand.

๐Ÿ›ก

Agents never act alone on what matters

Every agent's permissions are visible up front. Anything with a real external effect โ€” sending a message, publishing, spending โ€” waits for a human by default.

How data is protected

01

Encryption everywhere

Data is encrypted at rest (AES-256) and in transit (TLS 1.2+). Encryption keys are managed separately from application data.

02

Data residency, set once

Choose a storage region per organization โ€” US or EU today, more available on Enterprise plans. Set at the org level so it can't drift out of sync with a workspace-level setting.

03

PII handling

Optional automatic redaction of common PII patterns before storage, configurable per workspace โ€” on by default for templates like Sales & GTM where customer data enters immediately.

04

Enterprise identity

SAML/OIDC single sign-on and SCIM provisioning on Enterprise plans. When SSO is enforced for your domain, password and social login are automatically disabled for anyone matching it โ€” regardless of which login method they try.

05

Guest access is scoped tightly

A shareable session link grants access to that session only, as a time-boxed guest โ€” never silent workspace membership. Any broader access is an explicit, off-by-default choice.

What this looks like day to day

  • โœ“Block a compromised API key instantly, platform-wide
  • โœ“Revoke every active session for a user in one action
  • โœ“Configure an IP allowlist per organization
  • โœ“Export a full compliance-ready audit report on demand
  • โœ“See exactly what an AI agent is and isn't allowed to do
  • โœ“Set data retention policy once per workspace, enforced automatically

This page is the summary. For the full technical detail โ€” tenant isolation architecture, encryption specifics, our secure development pipeline, and compliance mapping โ€” see the complete Trust Center.

Visit the Trust Center โ†’