Trust Center
Source-grounded readiness, open to inspection.
Technical security controls, provider inventory, draft RFP answers, and self-verification in one place. Certifications, contracts, and live operations require separate evidence.
Compliance
Technical privacy controls and readiness mappings exist; no external certification is claimed.
- 0 external reports in repository
- 0 evidenced external audits in progress
- 30 RFP questions pre-answered
- DPA template present; execution required separately
Open compliance →Security
Defense in depth across encryption, identity, isolation, audit, and infrastructure. Verifiable live from your browser.
- AES-256-GCM at rest · TLS 1.2+ in transit
- Row-Level Security on 149 workspace tables
- Hash-chained audit entries
- Configuration objectives: RTO 4h · RPO 15m; verify live
Open security →Privacy
Configurable data regions and an open provider inventory; active providers and contracts require live verification.
- 12 providers marked active in the source inventory
- Change-notice process documented as a template
- Self-service GDPR data export
- DPIA and incident-response templates present
Open privacy →Bug bounty
Responsible-disclosure channel and safe-harbor terms; rewards are not guaranteed.
- Scope: orconic.com + *.orconic.com production
- Rewards only when confirmed in writing
- Response objectives are described in the disclosure policy
- Safe harbor for good-faith research
Open bug bounty →The full Trust Pack PDF
A repository-generated PDF covering security controls, provider inventory, readiness status, SBOM summary, and contract templates. It does not contain live operational evidence.
Embed the live status badge: <img src="https://orconic.com/trust/badge.svg" />