Security & Compliance

Your data never has to
leave the building

Voice data is among the most sensitive material an organisation holds, identity, health, finances, sometimes emergencies. OrOn is architected so that the strongest answer to 'where does the data go' is simply: nowhere.

Security shield with a lock protecting the voice platform core
100%On-premise capable
EncryptedIn transit & at rest
ImmutableAudit trail
Air-gapSupported
How it is secured

Controls your review board
will actually ask about

We wrote this page from the questions we get in enterprise and government security reviews, in roughly the order they get asked.

Encryption everywhere

Industry-standard encryption in transit and at rest, for audio, transcripts and derived data. Key management integrates with your existing infrastructure.

Data residency by architecture

On-premise deployment means residency is a property of the system, not a clause in a contract. Nothing crosses a border because nothing crosses your firewall.

Immutable audit trail

Every conversation turn is logged with timestamp, stage latencies, confidence scores and escalation reasons, append-only, exportable for oversight or FOI.

Role-based access and SSO

SAML and OIDC single sign-on, granular roles for operations, compliance and engineering, with all access itself logged.

Retention you control

Configurable retention and deletion policies per data class, with verifiable deletion. Recordings can be discarded immediately after processing if policy requires.

Air-gapped operation

For defence, emergency services and classified environments, the full stack runs with no outbound network path at all.

How it works

Three deployment perimeters

Pick the one your policy allows. Agent behaviour is identical across all three.

Managed cloud

We operate the infrastructure under our security controls. Fastest path, suitable for non-regulated workloads.

Your VPC

The stack runs inside your cloud account, your network boundary, your IAM. We manage the software, you own the perimeter.

On-premise

Your hardware, your data centre, no external calls. Standard for government, enterprise and defence.

Air-gapped

On-premise with no outbound path whatsoever, including for updates, which are applied through your controlled process.

  • Encrypted in transit and at rest
  • SAML / OIDC single sign-on with role-based access
  • Immutable, exportable audit log of every turn
  • Configurable retention with verifiable deletion
  • Penetration test reports available under NDA
  • DPA, BAA and NDA available on request
FAQ

Security questions

Straight answers. Anything missing? Write to Sales@or-on.io.

Wherever you choose. In on-premise deployment it never leaves your data centre, no external inference calls, no third-party cloud, no cross-border transfer. In cloud deployment you select the region and we can restrict processing to it contractually and technically.

No. Customer conversations are never used to train shared or foundation models. Where you want your own agent to improve on your traffic, that tuning is scoped entirely to your deployment and your data, and it is opt-in.

GDPR, HIPAA (with BAA), and local health and public-sector data regimes including Israeli privacy law. On-premise deployment satisfies most residency and sovereignty requirements by construction. Documentation is available for your review board under NDA.

You configure it per data class. Recordings can be deleted immediately after processing, transcripts retained only as long as your policy requires, and audit metadata kept for the period your oversight regime demands. Deletion is verifiable.

Yes. We support customer-run penetration testing against a staging deployment, and share our own most recent third-party test results under NDA.

Contact

Get the security documentation pack

Tell us the use case and the volume. We come back within one business day with a scoped pilot, a timeline and a number.

Contact Us

Accessibility