Security & Trust
ORQADOS is designed to protect the confidentiality, integrity and appropriate use of customer information.
This page describes security and operational controls currently implemented in the platform. It does not represent a certification or guarantee of absolute security.
Workspace isolation
Each customer's workspace is logically isolated from other customer workspaces. Application-level access controls scope customer data, including contacts, conversations and documents, to the authorised workspace. ORQADOS is designed to prevent one customer from accessing another customer's data.
Credential handling
Third-party credentials and access tokens for services such as Meta, Google and other connected providers are stored using ORQADOS's encrypted credential-storage mechanism. Stored secret values are not displayed back to users after capture and are excluded from application logging and ordinary browser-facing application responses.
Encryption
Network traffic between users and ORQADOS is protected using TLS. Sensitive provider credentials and access tokens stored by ORQADOS are encrypted at rest within the platform's credential-storage system.
Access control
Workspace access is role-based, with server-side authorisation and capability checks applied to protected operations. User-interface controls are not relied upon as the sole means of enforcing permissions.
Human control and approvals
- Outbound messaging and other configured workflows may require human approval depending on the workspace's policies and workflow settings.
- Valid opt-out and do-not-contact instructions are enforced through ORQADOS's central suppression controls and cannot be bypassed by ordinary campaign or nurture workflows.
- Where human handover is supported for a conversation, an authorised user can take over the conversation and automated nurture or AI responses are paused in accordance with configured handover rules.
Audit and event logging
ORQADOS records audit and operational events for material platform actions such as approvals, messaging activity, configuration changes and other supported administrative actions. Audit records may include the acting user, action, relevant resource and timestamp.
Messaging compliance
WhatsApp integrations use Meta's official WhatsApp Business Platform. Where WhatsApp policy requires a template for business-initiated messaging, ORQADOS uses an eligible Meta-approved template and verifies template status against provider data. ORQADOS is designed to operate within applicable provider messaging policies, consent requirements, quality controls and messaging limits.
Third-party providers
ORQADOS relies on selected third-party service providers and connected platforms to operate portions of the service, including Meta for WhatsApp functionality, Google where customers connect Google services, AI service providers, and infrastructure providers. Their respective roles and the categories of information involved are described further in our Privacy Policy.
Data retention and deletion
Customers may disconnect connected services and request deletion of their workspace in accordance with our account-deletion process. Certain information may be retained for a limited period where required for security, fraud prevention, backup integrity, legal compliance or the establishment, exercise or defence of legal claims. See Data Deletion & Account Removal for further information.
Security incidents
ORQADOS maintains processes for investigating suspected security incidents and taking appropriate containment and remediation measures. Where applicable law requires notification of an affected customer or regulatory authority, ORQADOS will take the required notification steps.
Requests from public authorities
ORQADOS may receive requests from law-enforcement agencies, regulators, courts or other public authorities seeking personal data held in the platform. ORQADOS has not received any such request to date. The process below applies to any request received.
Review of legality. Every request is reviewed for legal validity before any personal data is disclosed. ORQADOS assesses whether the request comes from an authority with jurisdiction over ORQADOS or the data concerned, whether it is made under a legal instrument that compels disclosure, whether it has been properly served, and whether it is within its own stated scope. Personal data is not disclosed in response to an informal or voluntary request unless disclosure is separately permitted by applicable law.
Challenging unlawful requests. Where ORQADOS considers a request to be unlawful, defective, overbroad or inconsistent with applicable law, ORQADOS will seek clarification or narrowing of the request and will refuse or challenge it through the available legal channels, taking legal advice where appropriate.
Data minimisation. Where disclosure is legally required, ORQADOS discloses only the specific records falling within the scope of the request. ORQADOS does not disclose an entire workspace, or unrelated contacts, conversations or documents, merely because they are held in the same system, and does not provide standing or bulk access to any authority.
Documentation. ORQADOS records each request received, including the requesting authority, the legal instrument relied on, the personal data sought, the legal reasoning applied, the individuals who handled the request, the decision taken and any data disclosed. These records are retained for the period required by applicable law.
Customer notification. Where ORQADOS holds the personal data as a service provider to a business customer, ORQADOS will inform that customer of a request relating to its workspace and, where lawful and practicable, allow the customer to respond before ORQADOS discloses any data, unless notification is prohibited by law or by the terms of the request.
No absolute security guarantee
No online service can guarantee absolute security. ORQADOS maintains technical and organisational safeguards designed to reduce security risks and reviews those safeguards as the platform develops. Customers are responsible for protecting their account credentials, connected services and authorised-user access.
Certifications
ORQADOS does not currently claim third-party certifications such as ISO 27001 or SOC 2. This page will be updated if that position changes.
Reporting a security concern
Please report suspected vulnerabilities or security incidents to [email protected]. We welcome responsible disclosure and will review reported security concerns as reasonably practicable.