Controls, certifications and paperwork — with their real status.
Three lists, kept honest: what is implemented today and on which plans, what is in progress with a third party, and what is available contractually on Enterprise. Nothing in progress is presented as a badge.
Implemented. In progress. Roadmap.
- ✓ Encryption
- ✓ Tenant isolation
- ✓ Audit logging
- ✓ Backups (dedicated configurations)
- ✓ Point-in-time recovery (dedicated configurations)
- ✓ Data residency
- … SOC 2 Type 1 (auditor engaged; letter and timeline on request)
- … ISO 27001 (certification body engaged; letter and timeline on request)
- ○ HIPAA Business Associate Agreement
- ○ GDPR Data Processing Agreement
- ○ Customer-managed encryption keys
- ○ Custom retention and quotas
Implemented today. Scope stated on each.
Encryption
TLS 1.2+ in transit · AES-256 at rest · customer-managed keys on Enterprise.
Tenant isolation
Every dedicated configuration is single-tenant, region-isolated: its own compute, storage, hostname and bearer token. Free and Starter run on shared, scale-to-zero infrastructure.
Audit logging
per-request audit log on every configuration — who called what, when, with which key.
Backups
Dedicated configurations: encrypted nightly snapshots, included; kept inside the instance's region.
Point-in-time recovery
Dedicated configurations: opt-in; restores to a 5 s boundary with retention up to 35 days. Free and Starter do not include point-in-time recovery.
Data residency
Data, transaction logs, backups and the natural-language compile step stay in the region you choose.
Everything a reviewer asks for first.
Tenancy model, credential handling, what the audit log records, retention, single-row CAS.
What we collect about you as a customer and how it is used.
Roles, sub-processing and transfer terms under GDPR.
The governing document, including the availability commitments.
Availability, recovery and support commitments per configuration.
Live probe results per region.
Found something? Tell us first.
Report vulnerabilities to security@originchain.ai with steps to reproduce. We acknowledge every report, keep you informed until it is resolved, and will not pursue action against research conducted in good faith that respects customer data.
- → originchaindb.com (originchain.ai redirects to it), app.originchain.ai and api.originchain.ai
- → The published SDKs (TypeScript, Python, Go)
- → Your own instance — never another customer's
Denial of service, social engineering, physical attacks, and findings that require access to another tenant's data.
Security questionnaire in your inbox? Forward it.
We answer standard questionnaires and walk your security team through the architecture on a call.