Security isn't a feature: it's our foundation

Orden AI is built for regulated industries where data sovereignty, compliance, and access control aren't optional. We design for air-gapped networks, strict audit requirements, and zero-trust architectures from day one.

Built for regulated industries

Role-Based Access Control

Every record has RBAC. Users only see data they're authorized to access. No exceptions.

  • Granular permissions at document, field, and collection levels
  • Support for clearance-level and need-to-know restrictions
  • Automatic access inheritance and group-based policies

Enterprise Authentication

Integrate with your existing identity infrastructure seamlessly.

  • OAuth2/OIDC for modern SSO
  • LDAP/Active Directory federation
  • Multi-factor authentication (TOTP, SMS, hardware tokens)
  • PKI/CAC card authentication for government environments
  • Session management with configurable timeouts

Data Encryption

Your data is encrypted everywhere: at rest, in transit, and in use.

  • TLS 1.3 for all network traffic
  • AES-256 encryption for data at rest
  • Encrypted backups with separate key management
  • Support for customer-managed encryption keys

Audit & Compliance

Complete audit trail for every action, with tamper-proof logging.

  • Full audit logs for access, modifications, and exports
  • Immutable audit trail with cryptographic signing
  • Configurable retention periods
  • Real-time alerting for suspicious activity
  • Brute force and anomaly detection

Deployment Sovereignty

Run Orden AI anywhere you need. Your data never leaves your control.

  • On-premises deployment (bare metal or VM)
  • Private VPC in AWS, GCP, or Azure
  • Air-gapped network support
  • SCIF-ready configurations
  • No outbound network requirements

Compliance Ready

Built to meet the requirements of highly regulated industries.

  • NIST 800-171-aligned controls
  • FedRAMP-aligned architecture
  • HIPAA-aligned safeguards
  • SOC 2 Type II-aligned practices
  • GDPR- and CCPA-aligned data handling
  • FAR/DFARS contract language support

Governing autonomous agents, not just human users

Traditional security controls who can see data. Orden adds a second layer: what an AI agent is allowed to do, and a permanent, glass-box record of every decision it made, auditable the same way a human action would be.

Autonomy That Only Tightens

One dial widens what an agent may do unattended. Organization and team policy can only narrow it, and a hard floor on outbound and destructive actions never lifts, whatever the dial, the rules, or a per-tool exemption say.

  • Autonomy set per agent, checked against org and team policy on every action
  • Most-restrictive-rule-wins across every applicable policy layer
  • Outbound and destructive actions never run unattended, full stop

An Agent Can Never Outrank Its Owner

Every agent's permissions are validated at grant time and recomputed continuously against its owner's current access: an agent can never hold a right its owner doesn't.

  • Grant ceiling enforced at assignment and re-checked on every run
  • Owner demoted or offboarded: the agent is flagged degraded with a named reason
  • A short-lived signed identity on every activation, with permissions already intersected

Budgets, Rate Limits, and a Kill Switch

Every agent carries a spend cap, a token cap, a rate limit, and a concurrency limit, shown against live consumption, not a theoretical ceiling. One control stops every agent in the organization at once.

  • Monthly spend, daily tokens, hourly rate, concurrency: enforced by the runtime, not a UI toggle
  • A refused activation is itself audited, so "why did it stop" is always answerable
  • Org-wide or team-wide kill switch cancels work in flight, releases only what it stopped

Glass-Box, Not Black-Box

Every action an AI agent takes is logged with the same rigor as a human user's: per-node inputs, outputs, cost, and duration, pinned to the exact pipeline version that produced them.

  • Full run history, replayable node by node, for every agent action
  • Denials are recorded too: the trail includes what was attempted and refused, not just what succeeded
  • Every consequential decision traces to its trigger, the agent, and the policy it was checked against

Secure by design

Every layer of Orden AI is built with security and compliance in mind.

Network Layer

TLS 1.3, certificate pinning, DDoS protection, rate limiting, IP allowlisting

Authentication Layer

OAuth2/OIDC, SAML, LDAP/AD, MFA, session management, brute force protection

Authorization Layer

RBAC on every record, attribute-based access control, dynamic policies, principle of least privilege

Data Layer

Encryption at rest (AES-256), encrypted backups, secure deletion, data residency controls

Audit Layer

Immutable logs, real-time monitoring, anomaly detection, compliance reporting

Built Toward Compliance

We design and operate against the control frameworks our customers are held to. None of the below are completed third-party certifications yet; each reflects an architectural and operational target we build to today.

SOC 2 Type II-Aligned

Security, availability, and confidentiality controls modeled on the SOC 2 Type II framework

NIST 800-171-Aligned

Controls designed to protect Controlled Unclassified Information (CUI)

FedRAMP-Aligned Architecture

Architecture and controls aligned with the FedRAMP moderate baseline

HIPAA-Aligned Architecture

Built to support HIPAA safeguards for healthcare deployments

Questions about security?

Our security team is available to discuss your specific requirements and compliance needs.