Trust
Guardrails baked in.
This page describes the platform controls that ship with every ORION tenant. Maintained by the ADVNT team and updated as the platform evolves. Not a substitute for an independent audit.
SOC 2 Type II — ReadyGDPR-alignedNo companion agent
Shared responsibility
ADVNT runs the platform — identity, tenancy isolation, encryption, audit. Your team owns who you grant access to, which credentials you store, and which migration jobs you promote to live. Tenants set policy; ORION enforces it.
Credentials
Stored as vault references — never plaintext
- Raw credential values are never displayed after entry
- Only the last 4 characters (key_hint) are shown for verification
- All credentials are references to the secret vault — not plaintext in the database
AI sessions
Headless and audited end-to-end
- AI sessions occur in Claude Desktop or Cowork — never inside ORION's web UI
- ORION renders conversation and message history read-only
- Every AI action is logged as one of four audited tiers, from read-only explanation to state-changing execution
- State-changing actions require human confirmation before execution
Migrations
Dry-run required. One running job per project.
- A live job (full or delta) requires a successful dry_run first
- Only one job per project may be in running status at a time
- Rollback is available for completed jobs within a platform-defined window
- Partner tenants see only their own projects — no cross-tenant visibility
Tenancy
Per-tenant isolation, enforced server-side
- Every server function resolves tenant_id from the authenticated session
- Row-level security gates all reads and writes by tenant
- Roles are stored separately from profiles and checked via a security-definer helper
Need a deeper review for procurement?
We share a security questionnaire and current sub-processor list on request. Reach out from your partner contact or open a session and ask.
Open app