This document is intended to be readable. Headings help navigation but do not limit the meaning of the sections beneath them.
Our security approach
Oryxa applies layered administrative, technical, and organizational safeguards based on the nature of the service and the data involved. Security is treated as an ongoing operating practice, not a one-time claim.
We do not claim certifications that have not been independently completed. Enterprise customers may request current security documentation and discuss contractual controls during procurement.
Core controls
- Identity and access: authenticated access, role-aware permissions, scoped connected accounts, and least-privilege service access.
- Data protection: encryption in transit, protected storage configurations, secrets management, and separation of customer access.
- Application security: input validation, dependency maintenance, logging, rate controls, and review of sensitive changes.
- Agent controls: bounded tools, explicit permissions, approval paths for sensitive actions, and visible activity records.
- Operational resilience: monitoring, backups where appropriate, incident procedures, and recovery planning proportionate to the service.
Controls can vary by deployment, plan, connected service, and customer configuration. Specific contractual commitments belong in an order form or security addendum.
Customer security responsibilities
Customers must protect credentials, use appropriate authentication settings, review member access, limit integration permissions, classify data before submission, and promptly remove users or connections that no longer need access.
Customers should require human approval for consequential actions, validate AI-generated material, maintain secure endpoints, and report suspected compromise without delay.
Security incidents
We investigate suspected incidents, take reasonable containment and remediation steps, preserve relevant evidence, and notify affected customers as required by applicable law and contract. Customer notifications will include available information reasonably needed to understand the event and coordinate a response.
Customers remain responsible for notifications relating to their own systems, users, and role as controller or data fiduciary unless the parties agree otherwise.
Responsible vulnerability disclosure
If you believe you found a security vulnerability, email the address below with the subject Security vulnerability. Include the affected URL or feature, reproduction steps, potential impact, and a safe way to contact you.
Please avoid accessing data that is not yours, disrupting service, using social engineering, degrading availability, or publicly disclosing an unresolved issue. Give us reasonable time to investigate and remediate before publication.
Good-faith research
We will not pursue legal action against good-faith security research that follows this policy, avoids privacy and availability harm, reports promptly, and complies with applicable law. This statement does not authorize access to third-party systems or data and does not waive rights concerning extortion, deception, or reckless conduct.
Talk to a person.
For privacy, contractual, security, or policy questions, contact hello@oryxa.in.