Source permissions
Choose every system OrthancIQ can read: product, billing, CRM, support, documentation, exports, or approved data-agent sources.
Atlas can move quickly without becoming a black box. Every data source, retained field, action permission, approval threshold, and escalation path is scoped, logged, and reviewable.
SOC 2 status. OrthancIQ does not currently claim completed SOC 2 certification. Current controls, architecture documentation, and the security roadmap are available under NDA.
Data access, retained fields, model inputs, action permissions, approval thresholds, and escalation policies are explicit parts of the OrthancIQ control plane.
Brain Engine decisions remain tied to the customer signals and model state that produced them. Atlas actions remain tied to the decision, permission, owner, and approval policy that authorized them.
Each customer’s data is logically isolated, with boundaries enforced at the data and application layers.
Data is encrypted in transit with TLS and at rest with AES-256, including backups where applicable.
Access and key actions are logged with timestamps and actor identity for review.
Role-based access with least-privilege defaults and MFA for internal access.
Retention windows for raw inputs and derived artifacts are defined during onboarding.
You can request deletion of your data and model artifacts. We confirm completion and timelines in writing.
Encrypted backups and recovery procedures protect against accidental data loss.
A documented incident-response process defines severity, ownership, escalation, and customer notification.
We support vendor reviews with documentation, questionnaires, and an NDA-backed controls overview.
Every stage is scoped, encrypted, and logged. Customer data powers your tenant-specific customer-state model and intervention memory; it is not used for shared-model training by default.
Your data builds your model. We do not use it to train shared or cross-customer models unless you explicitly opt in, in writing.
The value map, signal catalog, Brain Engine outputs, and Atlas evidence mappings are tied to your tenant and removed with your data on deletion.
We can support a serious review process with a controls overview, security questionnaire, subprocessor list, incident policy, and architecture summary under NDA.
Review Brain Engine inputs, Atlas action policies, architecture, and current controls before connecting the first customer signal path.