Skip to content
OrqLabs
Back to home

Security

Hand work to agents and stay in control

Where your data lives, how it is protected, who can access what and how costs are capped – explained plainly. We make no certification claims; we list the measures we actually apply.

Core measures

  • Hosted in the EU

    The application, database and files run in Hetzner data centres in Germany and Finland. Every connection is encrypted with TLS (HTTPS).
  • Encrypted credentials

    Tokens and API keys of the accounts you connect are stored encrypted with AES-256-GCM and are never returned in API responses. Passwords are hashed irreversibly with argon2.
  • Tenant isolation

    Every record belongs to one organization; the organization context is verified on every request and queries are scoped to it. No organization can see another organization's data.
  • Role-based access

    Owner, Admin, Member and Viewer roles decide who can run workflows, connect integrations or only watch. Programmatic access uses scoped API keys.
  • Audit log

    Critical events such as approvals, integration changes and admin actions are written to a filterable audit log with who did what and when.
  • No model training

    Your content is never used to train AI models. The Anthropic and OpenAI APIs do not train on data sent through the API by default either.
  • Human approval

    Approval steps for publishing, outreach and strategy changes; the chatbot hands a conversation to a human when unsure. Auto-reply and auto-apply are off by default.
  • Cost caps

    Budget caps per run, agent and organization meter every model call; once a cap is reached new calls are refused, and a warning is sent at 80%.
  • Application security

    Inbound webhooks are verified by signature and outbound webhooks are HMAC-signed; requests agents make to external URLs are filtered against access to internal networks.

Your data stays yours

You can disconnect accounts at any time, ask for a copy of your data or have your account deleted. Tokens and keys are deleted the moment you disconnect; copies in backups are removed within 90 days at most. Details are in our privacy policy.

Read the privacy policy

Certifications and agreements

We do not hold an independent security certification (such as ISO 27001 or SOC 2) yet. On request we sign a KVKK- and GDPR-aligned Data Processing Agreement (DPA) and answer your enterprise security questionnaires.

If an incident happens

No system is entirely risk-free. If a security breach affects your data, we notify the relevant authority and you within the time limits set by KVKK and GDPR.

Sub-processors

The providers we work with to deliver the service. The current list always lives in our privacy policy.

ProviderPurposeLocation
Hetzner Online GmbHServer hosting, database and file storageEuropean Union (Finland/Germany)
Anthropic, PBCAI processing with Claude modelsUSA
OpenAI, L.L.C.GPT models, text embeddings and image generationUSA
Google LLC / Google WorkspaceSending service emailsEU and USA
Google Ireland Ltd. / Google LLC (Google Analytics 4)Website visit statistics (loaded only after cookie consent)EU and USA
Cloudflare, Inc.Domain name (DNS) serviceGlobal
Stripe, Inc.Card payments (when enabled)EU and USA

Responsible disclosure

If you believe you have found a vulnerability, please write to hello@orqlabs.com with the subject "Security report". We will confirm receipt, investigate the finding and keep you informed.

Send a security report
  • Test only with your own account and your own data.
  • Do not access, modify or delete other users' data.
  • No tests that degrade the service (load testing, spam, social engineering).
  • Keep the finding private until it is fixed; we are happy to coordinate disclosure afterwards.