Encryption everywhere
Industry-standard encryption in transit and at rest, for audio, transcripts and derived data. Key management integrates with your existing infrastructure.
Voice data is among the most sensitive material an organisation holds, identity, health, finances, sometimes emergencies. OrOn is architected so that the strongest answer to 'where does the data go' is simply: nowhere.
We wrote this page from the questions we get in enterprise and government security reviews, in roughly the order they get asked.
Industry-standard encryption in transit and at rest, for audio, transcripts and derived data. Key management integrates with your existing infrastructure.
On-premise deployment means residency is a property of the system, not a clause in a contract. Nothing crosses a border because nothing crosses your firewall.
Every conversation turn is logged with timestamp, stage latencies, confidence scores and escalation reasons, append-only, exportable for oversight or FOI.
SAML and OIDC single sign-on, granular roles for operations, compliance and engineering, with all access itself logged.
Configurable retention and deletion policies per data class, with verifiable deletion. Recordings can be discarded immediately after processing if policy requires.
For defence, emergency services and classified environments, the full stack runs with no outbound network path at all.
Pick the one your policy allows. Agent behaviour is identical across all three.
We operate the infrastructure under our security controls. Fastest path, suitable for non-regulated workloads.
The stack runs inside your cloud account, your network boundary, your IAM. We manage the software, you own the perimeter.
Your hardware, your data centre, no external calls. Standard for government, enterprise and defence.
On-premise with no outbound path whatsoever, including for updates, which are applied through your controlled process.
Wherever you choose. In on-premise deployment it never leaves your data centre, no external inference calls, no third-party cloud, no cross-border transfer. In cloud deployment you select the region and we can restrict processing to it contractually and technically.
No. Customer conversations are never used to train shared or foundation models. Where you want your own agent to improve on your traffic, that tuning is scoped entirely to your deployment and your data, and it is opt-in.
GDPR, HIPAA (with BAA), and local health and public-sector data regimes including Israeli privacy law. On-premise deployment satisfies most residency and sovereignty requirements by construction. Documentation is available for your review board under NDA.
You configure it per data class. Recordings can be deleted immediately after processing, transcripts retained only as long as your policy requires, and audit metadata kept for the period your oversight regime demands. Deletion is verifiable.
Yes. We support customer-run penetration testing against a staging deployment, and share our own most recent third-party test results under NDA.
Tell us the use case and the volume. We come back within one business day with a scoped pilot, a timeline and a number.
Contact UsTwo minutes. We reply within one business day.
Your enquiry landed with our sales team. We reply within one business day.