Trust Center

Enterprise Security & Compliance at Oronts

Security controls are scoped per engagement and documented before production access: EU hosting, encryption in transit, least privilege, and audit logging, with a DPA plus technical and organizational measures (TOM) available on request.

EU
Hosting (Render Frankfurt)
AVV + TOM
Ready on request
100%
You own the code
1 business day
Response target
Security

Security at Every Layer

We build and deploy into your governed cloud tenancy rather than an Oronts-operated multi-tenant platform. Your identity, network, key, logging and backup services remain under your control; we configure the relevant controls, apply least-privilege access, and document the production setup so your reviewers can verify it directly.

Encryption

We configure standard encryption for data at rest and in transit, with keys held in your environment.

  • AES-256 or provider-standard encryption at rest
  • Modern TLS in transit, targeting TLS 1.3 where supported
  • Managed keys in your cloud KMS
  • SSL database connections
  • Encrypted backups where configured

Identity & Access

Access is governed through your identity provider and cloud IAM, with least privilege applied to production roles.

  • SSO, SAML and OAuth integration where required
  • Role-based access for users and services
  • MFA governed by your IdP for production access
  • MFA mandatory on Oronts tooling
  • Access reviewed per engagement

Audit & Monitoring

Logging and monitoring use your cloud-native services, with an auditable record of Oronts access.

  • Configured cloud audit logging
  • Failed-access and security-relevant alerts
  • Application audit events where required
  • Audit trail of Oronts access to your systems

Data Protection

Production data remains in your environment, with isolation, backup and deletion controls configured per engagement.

  • Single-tenant deployment in your cloud
  • Encrypted backups where supported
  • Point-in-time recovery where supported by the selected services
  • Documented retention and deletion handling, including GDPR Article 17

Network Protection

We configure network defenses inside your cloud tenancy using private networking, segmentation and restricted access paths.

  • Private networking and subnet segmentation
  • Default-deny security groups and ACLs
  • Restricted administrative access
  • WAF and DDoS protection through your cloud provider where available

DevSecOps

Security checks are built into the development and release workflow.

  • SAST and dependency scanning in CI
  • Container image vulnerability scanning for containerized deployments
  • Mandatory code review before merge
  • CI/CD checks enforced before deployment
  • Code signing where required by the engagement
Compliance

Certifications and compliance posture

Oronts holds no formal certifications yet. We build to recognized frameworks such as GDPR, the EU AI Act, and the OWASP guidelines, and we document our practices so your auditors can verify them directly.

TISAX and automotive scopes

Oronts is not TISAX-assessed. For projects that touch sensitive automotive data, we deliver within your assessed environment or work through an assessed partner. We would rather state this plainly than let silence imply otherwise.

Infrastructure

Global Infrastructure & Data Residency

Your data stays in your cloud account, region, and tenancy. We deploy into infrastructure you own and control, so residency follows the cloud and region you choose.

EU
In your EU tenancy (e.g. eu-central-1, eu-west-1)
Cloud provider
Your cloud account
Compliance Standards
GDPRData residency in your region
UK
In your UK tenancy (e.g. eu-west-2)
Cloud provider
Your cloud account
Compliance Standards
UK GDPRData residency in your region
Gulf / Middle East
In your Gulf tenancy (e.g. me-south-1, me-central-1)
Cloud provider
Your cloud account
Compliance Standards
Local data protectionData residency in your region
APAC
In your APAC tenancy (e.g. ap-southeast-1)
Cloud provider
Your cloud account
Compliance Standards
Local data protectionData residency in your region
US
In your US tenancy (e.g. us-east-1)
Cloud provider
Your cloud account
Compliance Standards
Data residency in your region
AI Ethics

Responsible AI Principles

Our commitment to ethical, transparent, and trustworthy AI

Transparency

Clear documentation of AI capabilities, limitations, and decision processes

Fairness

Regular bias testing and mitigation strategies across all models

Privacy

Data minimization and purpose limitation in AI training and inference

Accountability

Human oversight and clear responsibility chains for AI decisions

Safety

Comprehensive testing, red-teaming, and guardrails for all AI systems

Sustainability

Optimized models and green computing practices to minimize environmental impact

Practices

Security Practices in Detail

A transparent look at the specific protective measures we implement across every client engagement. These controls reflect our commitment to safeguarding client data, maintaining system integrity, and meeting regulatory requirements.

Encryption Standards

Data at rest is protected with AES-256 or provider-standard encryption, and data in transit uses modern TLS, targeting TLS 1.3 with forward secrecy where supported. Database connections use SSL/TLS. Backups are encrypted with separate keys in your cloud provider's managed key service, isolated from the data they protect. Key rotation and recovery are defined with separated roles, documented ownership and governed access paths in your cloud tenancy.

Access Control and Identity Management

We apply least privilege across the systems we work in. Oronts team access is role-based, reviewed regularly and protected with multi-factor authentication on our internal tools and cloud access. In client environments, access is gated through agreed roles, logged for auditability and removed through defined offboarding procedures when a team member leaves or an engagement ends. Where required, we integrate with your SAML 2.0 or OAuth 2.0 single sign-on so access governance remains centralized in your identity provider.

Continuous Monitoring and Incident Response

Monitoring and alerting are configured in your cloud using native services and agreed project tooling to surface failed access, anomalies and performance issues. We maintain an incident response plan with severity levels, escalation paths and communication templates. Response coverage, ownership and resolution targets are agreed per engagement. For incidents affecting your environment, we provide a structured review with findings, corrective actions and follow-up owners. Tooling can include OpenTelemetry for tracing, Prometheus for metrics and Grafana for visualization, with alert routing defined in the operating model.

Data Handling and Privacy Compliance

Oronts processes personal data in accordance with the EU General Data Protection Regulation (GDPR). Where other regimes such as the California Consumer Privacy Act apply to a client, the relevant obligations are handled per engagement. Data Processing Agreements (DPAs) are executed with all clients before handling personal data. Our systems support data subject access requests, right to erasure, data portability, and consent management. We maintain records of processing activities and conduct Data Protection Impact Assessments for high-risk processing operations. Personal data minimization is a core design principle: we collect only what is necessary and retain it only as long as required. All subprocessors are contractually bound to the same privacy standards we uphold.

Secure Development Lifecycle

Protective measures are integrated into every phase of our development process. During design, we conduct threat modeling sessions to identify potential attack vectors and rank them by likelihood and impact. During development, automated static analysis (SAST) and dependency scanning run on every pull request, blocking merges that introduce known vulnerabilities. Before deployment, dynamic application testing (DAST) validates that the running application resists common attacks listed in the OWASP Top 10. We follow documented secure coding guidelines. Code reviews require at least one reviewer with domain expertise, and all changes are traced through version control with signed commits.

Infrastructure and Network Safeguards

We deploy applications into single-tenant private networks in your cloud tenancy, with default-deny security groups and access control lists as the baseline. Where your cloud or CDN provides them, we configure a Web Application Firewall and edge DDoS protection tuned to the application. Container images are scanned for vulnerabilities before deployment. External penetration testing can be arranged per engagement and after significant infrastructure changes. Runtime monitoring can be configured where your platform supports it.

Business Continuity and Disaster Recovery

We maintain documented disaster recovery runbooks for production systems and test them through periodic failover drills. Recovery objectives are agreed per engagement in the service agreement rather than promised as a blanket guarantee. Automated backups run on configurable schedules with encrypted off-site replication. Blue-green deployment strategies support low-risk releases and rollback. Each client environment can include health check endpoints, automated failover triggers, and capacity planning reviews.

Vendor and Supply Chain Risk Management

We maintain a current registry of all third-party vendors and subprocessors who may access or process client data. Each vendor undergoes a risk assessment before onboarding that evaluates their data protection practices, financial stability, and compliance posture. Clients are notified 30 days before any new subprocessor is engaged, with the right to object. Open-source dependencies are tracked using software composition analysis tools. Dependency updates are reviewed weekly, and critical patches are applied within 48 hours of disclosure. We follow supply chain integrity practices including verifiable build pipelines and artifact signing.

Data

Data Handling Transparency

We believe you should know exactly how your data is handled at every stage of our engagement. Transparency in data management builds trust and helps you meet your own compliance obligations.

Data Classification

All client data is classified into sensitivity tiers (public, internal, confidential, restricted) at the start of every engagement. Each tier has defined handling requirements for storage, transmission, access, and disposal. Classification labels are applied automatically where possible and reviewed during quarterly audits.

Data Residency and Sovereignty

Client data is stored in the geographic region specified in the service agreement. It is never transferred outside that region without explicit written consent. EU client data remains within EU cloud regions. We support multi-region architectures for organizations with global operations, ensuring each region meets local regulatory requirements.

Data Retention and Disposal

We retain client data only for the duration specified in the service agreement plus a 30-day grace period for orderly transition. Upon project completion or contract termination, all data is securely deleted using cryptographic erasure methods that render data unrecoverable. A certificate of destruction is provided upon request. Backup copies follow the same retention schedule and disposal procedures.

Subprocessor Management

We maintain a current list of all subprocessors who may access client data. Clients are notified 30 days before any new subprocessor is engaged, with the right to object. All subprocessors are contractually bound to the same data protection standards we uphold. Annual reviews verify ongoing compliance.

Availability & Performance

99.9%
Uptime SLA target

Operational practices

How we run and monitor production systems. This is a description of our operational practices, not a live status feed.

API
Web application
AI services
Data processing

Security Vulnerability Disclosure

Found a security issue? We support responsible disclosure. Our policy sets out scope, rules of engagement, and response expectations. We aim to acknowledge valid reports promptly and to share a remediation plan after triage.

Corporate identity

The entity you contract with, verifiable in the public register.

Legal entity
Oronts GmbH
Commercial register
Amtsgericht München, HRB 288224
Managing director
Refaat Al Ktifan
Registered office
Leopoldstr. 31, 80802 Munich, Germany
General contact
office@oronts.com
Security contact
security@oronts.com

Subprocessors and key providers

The services that process data when you use oronts.com or work with us. The contractual basis is available on request as part of the DPA.

ProviderPurposeLocation and regionSafeguard
RenderHosting and delivery of oronts.comEU (Frankfurt)DPA with standard contractual clauses
Google WorkspaceBusiness email and internal documentsEU (Google Ireland)DPA, SCCs where applicable
Google Analytics 4Web analytics, loaded only after consentEU/USAConsent-gated, IP anonymization
OpenAILanguage model inference for the website assistantUSA/EUDPA with EU Standard Contractual Clauses, no training on inputs
Google CalendarMeeting scheduling via our booking linkEU (Google Ireland)Used only when you book
Continuity and exit

Continuity and exit

You stay in control of what we build together. No lock-in, clean handover whenever you choose.

You own the code and the data. Every repository and every artifact is yours from day one.

Full handover at any time. We hand over source, infrastructure definitions, and documentation on request, with no exit fee.

No vendor lock-in. We build on standard, portable technology so another team can take over.

Orderly 30-day transition. We support a structured handover over 30 days so your team or your next partner picks up without a gap.

Procurement and supplier reviews

Going through supplier onboarding? We answer security questionnaires and provide the DPA and this page as a printable document. Response within one business day.

Insurance certificate and company checks are available on request as part of a supplier review.

Start the supplier review