Absolute
Security
Security is not a feature — it is the foundation. Founders trust ORCA with their company's most sensitive data. We treat that trust seriously.
Data Ownership
Your company data, agent conversations, and outputs belong to you. We never use them to train AI models.
Default Isolation
Every organisation is isolated. DB policies and API checks ensure zero cross-boundary access.
Human Control
Approve First mode ensures no external action is taken without explicit human authorization.
Immutable Logs
Every significant action is recorded in an immutable audit trail that users can always access.
Infrastructure
Architecture
ORCA is built on SOC 2 Type II certified platforms. We leverage Vercel and Supabase to ensure enterprise-grade reliability and security.
Data Security
Standards
Your data is encrypted at every layer. Integration tokens are stored with authenticated encryption, and the database itself rejects queries that cross organisation boundaries.
AI Governance
ORCA scans every agent brief for known prompt injection patterns and blocks anomalous payloads.
Agents are strictly scoped to a single organisation\'s data. No agent can access cross-tenant history.
Agents cannot perform actions that the briefing user is not authorised to perform directly.
Access Control
PostgreSQL RLS ensures that the database itself rejects unauthorized cross-tenant queries.
Sessions expire after 7 days. Removed team members have access revoked globally within seconds.
All API nodes are rate-limited to prevent brute-force and resource exhaustion attacks.
Global Compliance Matrix
| Standard / Regulation | Status |
|---|---|
| Kenya Data Protection Act 2019 | ✓ COMPLIANT |
| GDPR (EU Data Privacy) | ✓ COMPLIANT |
| PCI-DSS (Via Paystack Integration) | ✓ COMPLIANT |
| SOC 2 Type II | REF: IN PROGRESS |
Incident Response
We monitor for anomalous activity 24/7. In the event of an incident affecting your data, we notify all affected Owners via email within 72 hours of verification.
Responsible Disclosure
If you discover a vulnerability, please report it to security@nexonic.com. We acknowledge all reports within 24 hours and do not pursue legal action against good-faith research.