Privacy Policy
Effective June 21, 2026
This Privacy Policy explains what data ORION collects, how we use and protect it, who we share it with, and the choices and rights you have. It applies to the ORION service operated by ADVNT.
1. Who we are
ORION is a multi-tenant ITSM intelligence platform operated by ADVNT (“ADVNT”, “we”, “us”). ADVNT runs and secures the platform infrastructure; each customer (“tenant”) controls the data and access within their own workspace. This policy explains how we handle personal data across the ORION service at orion.advnt.ai.
2. Data we collect
- Account data — your name, work email, and authentication identifiers, used to create and secure your account.
- Workspace data — the organization, projects, migration jobs, knowledge, and session records you create in ORION, scoped to your tenant.
- Connection credentials — credentials for connected ITSM systems (e.g. HaloITSM, ServiceNow) are stored as references to a secret vault, never as plaintext; only a last-4 hint is displayed for verification.
- Usage and diagnostic data — log, error, and performance telemetry used to operate, secure, and improve the service.
3. How we use data
- To provide, maintain, and secure the ORION service and your tenant workspace.
- To authenticate users and enforce role- and tenant-based access controls.
- To operate AI features within ORION's four-verb model (explain, route, unlock, act), where act-tier actions require human confirmation.
- To monitor reliability, investigate incidents, and prevent abuse.
- To communicate service, security, and account notices.
4. Sub-processors
We use a small set of vetted infrastructure providers to deliver ORION. Each processes data only as needed to provide their service:
- Supabase — managed Postgres database, authentication, and storage (data hosted in the United States, us-east-1).
- Lovable — application hosting and deployment.
- Anthropic — large-language-model processing for AI features invoked from a session.
- Your connected ITSM providers (e.g. HaloITSM, ServiceNow) — accessed only via credentials you supply.
5. Data residency & retention
Tenant data is hosted in the United States (us-east-1). We retain workspace data for the life of your account and delete or anonymize it within a commercially reasonable period after account closure, except where longer retention is required by law. Automated backups are retained on a rolling 7-day window.
6. Tenant isolation & security
- Every server request resolves your tenant from the authenticated session — never from client input.
- Row-level security gates reads and writes by tenant as a backstop.
- Roles are stored separately from profiles and checked via a security-definer helper.
- Credentials are vault references; service-role keys are server-only and never exposed to the browser.
7. Your rights
Depending on your jurisdiction (including under GDPR and CCPA), you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Tenant administrators can action most requests directly in-app; for anything else, contact us using the details below. We do not sell personal data.
8. Contact
Questions or privacy requests: privacy@advnt.ai. For a data-processing agreement or sub-processor list, contact legal@advnt.ai.