Enterprise Security & Compliance at Oronts
Security controls are scoped per engagement and documented before production access: EU hosting, encryption in transit, least privilege, and audit logging, with a DPA plus technical and organizational measures (TOM) available on request.
Security at Every Layer
We build and deploy into your governed cloud tenancy rather than an Oronts-operated multi-tenant platform. Your identity, network, key, logging and backup services remain under your control; we configure the relevant controls, apply least-privilege access, and document the production setup so your reviewers can verify it directly.
Encryption
We configure standard encryption for data at rest and in transit, with keys held in your environment.
- AES-256 or provider-standard encryption at rest
- Modern TLS in transit, targeting TLS 1.3 where supported
- Managed keys in your cloud KMS
- SSL database connections
- Encrypted backups where configured
Identity & Access
Access is governed through your identity provider and cloud IAM, with least privilege applied to production roles.
- SSO, SAML and OAuth integration where required
- Role-based access for users and services
- MFA governed by your IdP for production access
- MFA mandatory on Oronts tooling
- Access reviewed per engagement
Audit & Monitoring
Logging and monitoring use your cloud-native services, with an auditable record of Oronts access.
- Configured cloud audit logging
- Failed-access and security-relevant alerts
- Application audit events where required
- Audit trail of Oronts access to your systems
Data Protection
Production data remains in your environment, with isolation, backup and deletion controls configured per engagement.
- Single-tenant deployment in your cloud
- Encrypted backups where supported
- Point-in-time recovery where supported by the selected services
- Documented retention and deletion handling, including GDPR Article 17
Network Protection
We configure network defenses inside your cloud tenancy using private networking, segmentation and restricted access paths.
- Private networking and subnet segmentation
- Default-deny security groups and ACLs
- Restricted administrative access
- WAF and DDoS protection through your cloud provider where available
DevSecOps
Security checks are built into the development and release workflow.
- SAST and dependency scanning in CI
- Container image vulnerability scanning for containerized deployments
- Mandatory code review before merge
- CI/CD checks enforced before deployment
- Code signing where required by the engagement
Certifications and compliance posture
Oronts holds no formal certifications yet. We build to recognized frameworks such as GDPR, the EU AI Act, and the OWASP guidelines, and we document our practices so your auditors can verify them directly.
TISAX and automotive scopes
Oronts is not TISAX-assessed. For projects that touch sensitive automotive data, we deliver within your assessed environment or work through an assessed partner. We would rather state this plainly than let silence imply otherwise.
Global Infrastructure & Data Residency
Your data stays in your cloud account, region, and tenancy. We deploy into infrastructure you own and control, so residency follows the cloud and region you choose.
Responsible AI Principles
Our commitment to ethical, transparent, and trustworthy AI
Transparency
Clear documentation of AI capabilities, limitations, and decision processes
Fairness
Regular bias testing and mitigation strategies across all models
Privacy
Data minimization and purpose limitation in AI training and inference
Accountability
Human oversight and clear responsibility chains for AI decisions
Safety
Comprehensive testing, red-teaming, and guardrails for all AI systems
Sustainability
Optimized models and green computing practices to minimize environmental impact
Security Practices in Detail
A transparent look at the specific protective measures we implement across every client engagement. These controls reflect our commitment to safeguarding client data, maintaining system integrity, and meeting regulatory requirements.
Encryption Standards
Data at rest is protected with AES-256 or provider-standard encryption, and data in transit uses modern TLS, targeting TLS 1.3 with forward secrecy where supported. Database connections use SSL/TLS. Backups are encrypted with separate keys in your cloud provider's managed key service, isolated from the data they protect. Key rotation and recovery are defined with separated roles, documented ownership and governed access paths in your cloud tenancy.
Access Control and Identity Management
We apply least privilege across the systems we work in. Oronts team access is role-based, reviewed regularly and protected with multi-factor authentication on our internal tools and cloud access. In client environments, access is gated through agreed roles, logged for auditability and removed through defined offboarding procedures when a team member leaves or an engagement ends. Where required, we integrate with your SAML 2.0 or OAuth 2.0 single sign-on so access governance remains centralized in your identity provider.
Continuous Monitoring and Incident Response
Monitoring and alerting are configured in your cloud using native services and agreed project tooling to surface failed access, anomalies and performance issues. We maintain an incident response plan with severity levels, escalation paths and communication templates. Response coverage, ownership and resolution targets are agreed per engagement. For incidents affecting your environment, we provide a structured review with findings, corrective actions and follow-up owners. Tooling can include OpenTelemetry for tracing, Prometheus for metrics and Grafana for visualization, with alert routing defined in the operating model.
Data Handling and Privacy Compliance
Oronts processes personal data in accordance with the EU General Data Protection Regulation (GDPR). Where other regimes such as the California Consumer Privacy Act apply to a client, the relevant obligations are handled per engagement. Data Processing Agreements (DPAs) are executed with all clients before handling personal data. Our systems support data subject access requests, right to erasure, data portability, and consent management. We maintain records of processing activities and conduct Data Protection Impact Assessments for high-risk processing operations. Personal data minimization is a core design principle: we collect only what is necessary and retain it only as long as required. All subprocessors are contractually bound to the same privacy standards we uphold.
Secure Development Lifecycle
Protective measures are integrated into every phase of our development process. During design, we conduct threat modeling sessions to identify potential attack vectors and rank them by likelihood and impact. During development, automated static analysis (SAST) and dependency scanning run on every pull request, blocking merges that introduce known vulnerabilities. Before deployment, dynamic application testing (DAST) validates that the running application resists common attacks listed in the OWASP Top 10. We follow documented secure coding guidelines. Code reviews require at least one reviewer with domain expertise, and all changes are traced through version control with signed commits.
Infrastructure and Network Safeguards
We deploy applications into single-tenant private networks in your cloud tenancy, with default-deny security groups and access control lists as the baseline. Where your cloud or CDN provides them, we configure a Web Application Firewall and edge DDoS protection tuned to the application. Container images are scanned for vulnerabilities before deployment. External penetration testing can be arranged per engagement and after significant infrastructure changes. Runtime monitoring can be configured where your platform supports it.
Business Continuity and Disaster Recovery
We maintain documented disaster recovery runbooks for production systems and test them through periodic failover drills. Recovery objectives are agreed per engagement in the service agreement rather than promised as a blanket guarantee. Automated backups run on configurable schedules with encrypted off-site replication. Blue-green deployment strategies support low-risk releases and rollback. Each client environment can include health check endpoints, automated failover triggers, and capacity planning reviews.
Vendor and Supply Chain Risk Management
We maintain a current registry of all third-party vendors and subprocessors who may access or process client data. Each vendor undergoes a risk assessment before onboarding that evaluates their data protection practices, financial stability, and compliance posture. Clients are notified 30 days before any new subprocessor is engaged, with the right to object. Open-source dependencies are tracked using software composition analysis tools. Dependency updates are reviewed weekly, and critical patches are applied within 48 hours of disclosure. We follow supply chain integrity practices including verifiable build pipelines and artifact signing.
Data Handling Transparency
We believe you should know exactly how your data is handled at every stage of our engagement. Transparency in data management builds trust and helps you meet your own compliance obligations.
Data Classification
All client data is classified into sensitivity tiers (public, internal, confidential, restricted) at the start of every engagement. Each tier has defined handling requirements for storage, transmission, access, and disposal. Classification labels are applied automatically where possible and reviewed during quarterly audits.
Data Residency and Sovereignty
Client data is stored in the geographic region specified in the service agreement. It is never transferred outside that region without explicit written consent. EU client data remains within EU cloud regions. We support multi-region architectures for organizations with global operations, ensuring each region meets local regulatory requirements.
Data Retention and Disposal
We retain client data only for the duration specified in the service agreement plus a 30-day grace period for orderly transition. Upon project completion or contract termination, all data is securely deleted using cryptographic erasure methods that render data unrecoverable. A certificate of destruction is provided upon request. Backup copies follow the same retention schedule and disposal procedures.
Subprocessor Management
We maintain a current list of all subprocessors who may access client data. Clients are notified 30 days before any new subprocessor is engaged, with the right to object. All subprocessors are contractually bound to the same data protection standards we uphold. Annual reviews verify ongoing compliance.
Availability & Performance
Operational practices
How we run and monitor production systems. This is a description of our operational practices, not a live status feed.
Security Vulnerability Disclosure
Found a security issue? We support responsible disclosure. Our policy sets out scope, rules of engagement, and response expectations. We aim to acknowledge valid reports promptly and to share a remediation plan after triage.
Corporate identity
The entity you contract with, verifiable in the public register.
- Legal entity
- Oronts GmbH
- Commercial register
- Amtsgericht München, HRB 288224
- Managing director
- Refaat Al Ktifan
- Registered office
- Leopoldstr. 31, 80802 Munich, Germany
- General contact
- office@oronts.com
- Security contact
- security@oronts.com
Subprocessors and key providers
The services that process data when you use oronts.com or work with us. The contractual basis is available on request as part of the DPA.
| Provider | Purpose | Location and region | Safeguard |
|---|---|---|---|
| Render | Hosting and delivery of oronts.com | EU (Frankfurt) | DPA with standard contractual clauses |
| Google Workspace | Business email and internal documents | EU (Google Ireland) | DPA, SCCs where applicable |
| Google Analytics 4 | Web analytics, loaded only after consent | EU/USA | Consent-gated, IP anonymization |
| OpenAI | Language model inference for the website assistant | USA/EU | DPA with EU Standard Contractual Clauses, no training on inputs |
| Google Calendar | Meeting scheduling via our booking link | EU (Google Ireland) | Used only when you book |
Continuity and exit
You stay in control of what we build together. No lock-in, clean handover whenever you choose.
You own the code and the data. Every repository and every artifact is yours from day one.
Full handover at any time. We hand over source, infrastructure definitions, and documentation on request, with no exit fee.
No vendor lock-in. We build on standard, portable technology so another team can take over.
Orderly 30-day transition. We support a structured handover over 30 days so your team or your next partner picks up without a gap.
Procurement and supplier reviews
Going through supplier onboarding? We answer security questionnaires and provide the DPA and this page as a printable document. Response within one business day.
Insurance certificate and company checks are available on request as part of a supplier review.
Start the supplier review