Absolute
Security

Security is not a feature — it is the foundation. Founders trust ORCA with their company's most sensitive data. We treat that trust seriously.

01 — PRINCIPLE

Data Ownership

Your company data, agent conversations, and outputs belong to you. We never use them to train AI models.

02 — PRINCIPLE

Default Isolation

Every organisation is isolated. DB policies and API checks ensure zero cross-boundary access.

03 — PRINCIPLE

Human Control

Approve First mode ensures no external action is taken without explicit human authorization.

04 — PRINCIPLE

Immutable Logs

Every significant action is recorded in an immutable audit trail that users can always access.

Infrastructure
Architecture

ORCA is built on SOC 2 Type II certified platforms. We leverage Vercel and Supabase to ensure enterprise-grade reliability and security.

HostingVercel (SOC 2)
DatabaseSupabase (SOC 2)
DDoS ProtectionCloudflare / Edge
Minimum TLS1.3 for all nodes
Uptime Target99.9% Autonomous Runtime
Encryption at RestAES-256
Integration TokensAES-256-GCM
Data in TransitTLS 1.3 Minimum
Password HashingBCRYPT (Supabase Auth)
API SecurityHMAC Signature Verification

Data Security
Standards

Your data is encrypted at every layer. Integration tokens are stored with authenticated encryption, and the database itself rejects queries that cross organisation boundaries.

AI Governance

01 // INJECTION DETECTION

ORCA scans every agent brief for known prompt injection patterns and blocks anomalous payloads.

02 // CONTEXT ISOLATION

Agents are strictly scoped to a single organisation\'s data. No agent can access cross-tenant history.

03 // PERMISSION PROXY

Agents cannot perform actions that the briefing user is not authorised to perform directly.

Access Control

01 // ROW LEVEL SECURITY

PostgreSQL RLS ensures that the database itself rejects unauthorized cross-tenant queries.

02 // SESSION HYGIENE

Sessions expire after 7 days. Removed team members have access revoked globally within seconds.

03 // RATE LIMITING

All API nodes are rate-limited to prevent brute-force and resource exhaustion attacks.

Global Compliance Matrix

Standard / RegulationStatus
Kenya Data Protection Act 2019✓ COMPLIANT
GDPR (EU Data Privacy)✓ COMPLIANT
PCI-DSS (Via Paystack Integration)✓ COMPLIANT
SOC 2 Type IIREF: IN PROGRESS

Incident Response

We monitor for anomalous activity 24/7. In the event of an incident affecting your data, we notify all affected Owners via email within 72 hours of verification.

Responsible Disclosure

If you discover a vulnerability, please report it to security@nexonic.com. We acknowledge all reports within 24 hours and do not pursue legal action against good-faith research.