Skip to content
Trust

Guardrails baked in.

This page describes the platform controls that ship with every ORION tenant. Maintained by the ADVNT team and updated as the platform evolves. Not a substitute for an independent audit.

SOC 2 Type II — ReadyGDPR-alignedNo companion agent

Shared responsibility

ADVNT runs the platform — identity, tenancy isolation, encryption, audit. Your team owns who you grant access to, which credentials you store, and which migration jobs you promote to live. Tenants set policy; ORION enforces it.

Credentials

Stored as vault references — never plaintext

  • Raw credential values are never displayed after entry
  • Only the last 4 characters (key_hint) are shown for verification
  • All credentials are references to the secret vault — not plaintext in the database
AI sessions

Headless and audited end-to-end

  • AI sessions occur in Claude Desktop or Cowork — never inside ORION's web UI
  • ORION renders conversation and message history read-only
  • Every AI action is logged as one of four audited tiers, from read-only explanation to state-changing execution
  • State-changing actions require human confirmation before execution
Migrations

Dry-run required. One running job per project.

  • A live job (full or delta) requires a successful dry_run first
  • Only one job per project may be in running status at a time
  • Rollback is available for completed jobs within a platform-defined window
  • Partner tenants see only their own projects — no cross-tenant visibility
Tenancy

Per-tenant isolation, enforced server-side

  • Every server function resolves tenant_id from the authenticated session
  • Row-level security gates all reads and writes by tenant
  • Roles are stored separately from profiles and checked via a security-definer helper

Need a deeper review for procurement?

We share a security questionnaire and current sub-processor list on request. Reach out from your partner contact or open a session and ask.

Open app