trust center

Controls, certifications and paperwork — with their real status.

Three lists, kept honest: what is implemented today and on which plans, what is in progress with a third party, and what is available contractually on Enterprise. Nothing in progress is presented as a badge.

01 · status

Implemented. In progress. Roadmap.

implemented
  • Encryption
  • Tenant isolation
  • Audit logging
  • Backups (dedicated configurations)
  • Point-in-time recovery (dedicated configurations)
  • Data residency
in progress
  • SOC 2 Type 1 (auditor engaged; letter and timeline on request)
  • ISO 27001 (certification body engaged; letter and timeline on request)
contractual · enterprise
  • HIPAA Business Associate Agreement
  • GDPR Data Processing Agreement
  • Customer-managed encryption keys
  • Custom retention and quotas
02 · controls, and where they apply

Implemented today. Scope stated on each.

Encryption

TLS 1.2+ in transit · AES-256 at rest · customer-managed keys on Enterprise.

Tenant isolation

Every dedicated configuration is single-tenant, region-isolated: its own compute, storage, hostname and bearer token. Free and Starter run on shared, scale-to-zero infrastructure.

Audit logging

per-request audit log on every configuration — who called what, when, with which key.

Backups

Dedicated configurations: encrypted nightly snapshots, included; kept inside the instance's region.

Point-in-time recovery

Dedicated configurations: opt-in; restores to a 5 s boundary with retention up to 35 days. Free and Starter do not include point-in-time recovery.

Data residency

Data, transaction logs, backups and the natural-language compile step stay in the region you choose.

04 · responsible disclosure

Found something? Tell us first.

Report vulnerabilities to security@originchain.ai with steps to reproduce. We acknowledge every report, keep you informed until it is resolved, and will not pursue action against research conducted in good faith that respects customer data.

in scope
  • originchaindb.com (originchain.ai redirects to it), app.originchain.ai and api.originchain.ai
  • The published SDKs (TypeScript, Python, Go)
  • Your own instance — never another customer's
not in scope

Denial of service, social engineering, physical attacks, and findings that require access to another tenant's data.

Security questionnaire in your inbox? Forward it.

We answer standard questionnaires and walk your security team through the architecture on a call.