Back to home
Security
Hand work to agents and stay in control
Where your data lives, how it is protected, who can access what and how costs are capped – explained plainly. We make no certification claims; we list the measures we actually apply.
Core measures
Hosted in the EU
The application, database and files run in Hetzner data centres in Germany and Finland. Every connection is encrypted with TLS (HTTPS).Encrypted credentials
Tokens and API keys of the accounts you connect are stored encrypted with AES-256-GCM and are never returned in API responses. Passwords are hashed irreversibly with argon2.Tenant isolation
Every record belongs to one organization; the organization context is verified on every request and queries are scoped to it. No organization can see another organization's data.Role-based access
Owner, Admin, Member and Viewer roles decide who can run workflows, connect integrations or only watch. Programmatic access uses scoped API keys.Audit log
Critical events such as approvals, integration changes and admin actions are written to a filterable audit log with who did what and when.No model training
Your content is never used to train AI models. The Anthropic and OpenAI APIs do not train on data sent through the API by default either.Human approval
Approval steps for publishing, outreach and strategy changes; the chatbot hands a conversation to a human when unsure. Auto-reply and auto-apply are off by default.Cost caps
Budget caps per run, agent and organization meter every model call; once a cap is reached new calls are refused, and a warning is sent at 80%.Application security
Inbound webhooks are verified by signature and outbound webhooks are HMAC-signed; requests agents make to external URLs are filtered against access to internal networks.
Your data stays yours
You can disconnect accounts at any time, ask for a copy of your data or have your account deleted. Tokens and keys are deleted the moment you disconnect; copies in backups are removed within 90 days at most. Details are in our privacy policy.
Read the privacy policyCertifications and agreements
We do not hold an independent security certification (such as ISO 27001 or SOC 2) yet. On request we sign a KVKK- and GDPR-aligned Data Processing Agreement (DPA) and answer your enterprise security questionnaires.
If an incident happens
No system is entirely risk-free. If a security breach affects your data, we notify the relevant authority and you within the time limits set by KVKK and GDPR.
Sub-processors
The providers we work with to deliver the service. The current list always lives in our privacy policy.
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Server hosting, database and file storage | European Union (Finland/Germany) |
| Anthropic, PBC | AI processing with Claude models | USA |
| OpenAI, L.L.C. | GPT models, text embeddings and image generation | USA |
| Google LLC / Google Workspace | Sending service emails | EU and USA |
| Google Ireland Ltd. / Google LLC (Google Analytics 4) | Website visit statistics (loaded only after cookie consent) | EU and USA |
| Cloudflare, Inc. | Domain name (DNS) service | Global |
| Stripe, Inc. | Card payments (when enabled) | EU and USA |
Responsible disclosure
If you believe you have found a vulnerability, please write to hello@orqlabs.com with the subject "Security report". We will confirm receipt, investigate the finding and keep you informed.
Send a security report- Test only with your own account and your own data.
- Do not access, modify or delete other users' data.
- No tests that degrade the service (load testing, spam, social engineering).
- Keep the finding private until it is fixed; we are happy to coordinate disclosure afterwards.