Security & trust

Adaptive intelligence. Controlled agency. One governed system.

Atlas can move quickly without becoming a black box. Every data source, retained field, action permission, approval threshold, and escalation path is scoped, logged, and reviewable.

REVIEW
READY
Controls mapped
Guardrailed by design control set
AES
256
Encryption
TLS + AES-256
NO
TRAINING
Model training
Off by default
Security posture
Source permissionsRequired
Field and retention policiesRequired
Tenant isolationScoped per tenant
Encryption in transitTLS
Encryption at restAES-256
Audit loggingLogged
Least-privilege accessRBAC + MFA
Training on your dataOff by default
Data deletion on requestSupported

SOC 2 status. OrthancIQ does not currently claim completed SOC 2 certification. Current controls, architecture documentation, and the security roadmap are available under NDA.

Permission gates

You control what Brain Engine can learn from—and what Atlas can do.

Data access, retained fields, model inputs, action permissions, approval thresholds, and escalation policies are explicit parts of the OrthancIQ control plane.

01

Source permissions

Choose every system OrthancIQ can read: product, billing, CRM, support, documentation, exports, or approved data-agent sources.

02

Field and retention policies

Choose which fields Atlas can retain, redact, transform, or delete on a shorter schedule.

03

Identity and mapping review

Review account, user, subscription, event, and role mappings before they influence Brain Engine state and intervention decisions.

04

Action permissions

Define which actions Atlas may prepare, execute, or escalate—and which always require human approval.

05

Full audit trail

Data access, transformations, model decisions, approvals, actions, follow-ups, and outcomes remain reviewable.

Decision integrity

Every Brain Engine decision and Atlas action carries its evidence.

Brain Engine decisions remain tied to the customer signals and model state that produced them. Atlas actions remain tied to the decision, permission, owner, and approval policy that authorized them.

  • No fabricated customer history or hidden data expansion.
  • Brain Engine owns diagnosis and prioritization; Atlas owns the operating loop.
  • Brain Engine only reasons from authorized customer context.
  • New tracking and sensitive actions can remain approval-gated.
  • Current controls and the security roadmap are available for review under NDA.
Controls

Security controls are part of the product, not a slide afterthought.

Tenant isolation

Each customer’s data is logically isolated, with boundaries enforced at the data and application layers.

Encryption

Data is encrypted in transit with TLS and at rest with AES-256, including backups where applicable.

Audit logging

Access and key actions are logged with timestamps and actor identity for review.

Access controls

Role-based access with least-privilege defaults and MFA for internal access.

Data retention

Retention windows for raw inputs and derived artifacts are defined during onboarding.

Deletion on request

You can request deletion of your data and model artifacts. We confirm completion and timelines in writing.

Backups & recovery

Encrypted backups and recovery procedures protect against accidental data loss.

Incident response

A documented incident-response process defines severity, ownership, escalation, and customer notification.

Security review readiness

We support vendor reviews with documentation, questionnaires, and an NDA-backed controls overview.

Data lifecycle

Your data and tenant-specific intelligence stay inside your boundary.

Every stage is scoped, encrypted, and logged. Customer data powers your tenant-specific customer-state model and intervention memory; it is not used for shared-model training by default.

Ingest
over TLS
Isolate
per tenant
Encrypt
AES-256
Model
tenant-scoped
Retain
defined window
Delete
on request

No shared-model training by default

Your data builds your model. We do not use it to train shared or cross-customer models unless you explicitly opt in, in writing.

Brain Engine artifacts follow your tenant

The value map, signal catalog, Brain Engine outputs, and Atlas evidence mappings are tied to your tenant and removed with your data on deletion.

For your security team

Need to run vendor review before sending data?

We can support a serious review process with a controls overview, security questionnaire, subprocessor list, incident policy, and architecture summary under NDA.

Controls overview (Guardrailed by design)
Security questionnaire (CAIQ-style)
Subprocessor list
Architecture & data-flow summary
Incident-response policy

Run the OrthancIQ security review.

Review Brain Engine inputs, Atlas action policies, architecture, and current controls before connecting the first customer signal path.