SECURITY POSTURE

Enterprise-grade security for every workspace

OrgX is built for teams that demand verifiable controls, transparent operations, and rapid response. Below is the snapshot of our current security program.

Last updated June 24, 2026

Secure by design

We ship features through threat modeling, automated dependency scanning, and mandatory security reviews across every release train.

Least privilege by default

All production systems operate with scoped service accounts, short-lived credentials, and per-integration access controls for every workspace.

Observability everywhere

Audit logs, alerting, and response procedures help us detect, investigate, and remediate issues quickly.

Verifier-ready controls

The security review path is explicit.

Reviewers should not have to infer whether OrgX has scoped OAuth, audit history, exportability, permission boundaries, or a retention story. These are the concrete controls and routes we can point to today.

OAuth scopes

Connector access is scoped before it reaches the agent layer.

MCP pairing starts from authenticated user intent and moves through a consent step where connector permissions are approved before tools are exposed.

Review packet includes the consent flow, session-lifetime policy, and scope-to-tool mapping without publishing internal routes.

Permission boundaries

Every workspace-sensitive read is bounded by identity and ownership.

Workspace endpoints require auth, CSRF on writes, owner checks for workspace-scoped rows, and Supabase row-level security for persisted workspace data.

Review packet includes the control model and representative policy evidence without exposing internal handler names or privileged route inventory.

Audit trail proof

Sensitive mutations write durable audit rows.

Workspace API keys, budgets, SSO config, and plan reviews are captured in audit_log with actor, workspace, entity, event kind, reason, and timestamp.

Authenticated reviewers can request timestamped audit extracts through support or in-product export paths.

Data export

Exports are explicit endpoints, not hidden support work.

Usage exports, learned-workspace exports, and audit extracts are explicit authenticated workflows. Unsupported export surfaces fail closed instead of implying silent coverage.

Review packet lists available export types, formats, requester requirements, and expected response behavior without publishing internal route templates.

Retention policy

Retention is documented by data class and reviewed during security requests.

Backups, logs, transcripts, artifacts, learned preferences, and customer deletion requests have different retention paths so reviewers can see what stays and why.

35-day backup statement, artifact/log retention controls, deletion request workflow

Export walk-through

What a buyer gets during diligence

The export path is meant to be boring: authenticated, timestamped, no-store responses that can be attached to a security review without manual reconstruction.

  1. 01Sign in to OrgX and choose the workspace or center under review.
  2. 02Export billing usage as CSV from the authenticated billing export flow.
  3. 03Export learned workspace context as JSON from the authenticated workspace export flow.
  4. 04For audit evidence, request a timestamped audit extract scoped to the relevant workspace and entity class.
  5. 05Attach the CSV, JSON, and audit rows to the customer security packet with the generated timestamp intact.

System Assurances

Encryption & secrets

  • Modern TLS is enforced for customer-facing traffic, webhook delivery, and agent communication.
  • Customer data is encrypted at rest where supported by the underlying provider and protected by workspace access controls.
  • Production secrets are stored in managed secret systems, scoped by environment, and never requested through public support or review channels.

Infrastructure hardening

  • Production services sit behind edge protection, rate limiting, and monitored ingress controls.
  • Build and dependency checks run before release; critical security updates are prioritized through the release process.
  • Detailed deployment topology and privileged access patterns are disclosed only through controlled diligence channels.

Data lifecycle

  • Daily encrypted backups with 35-day retention and quarterly recovery drills.
  • Customer-controlled data deletion with hard-delete propagation inside 30 minutes.
  • Fine-grained retention controls for system logs, transcripts, and artifacts.

Processor review

Download the security review packet.

The one-pager summarizes controls, export routes, and processor coverage. The sub-processor page maps each provider to purpose, data categories, and operating controls for buyer diligence.

Incident response & transparency

Our response playbook is designed for high-velocity teams. We triage within minutes, communicate within SLA windows, and publish the outcomes so your stakeholders understand impact and remediation.

24/7 On-call Engineering
Detect

24/7 monitoring on auth, anomaly detection, and perimeter alerts using automated paging policies.

Stabilize

Isolate impacted services, rotate credentials, and enable maintenance mode where necessary.

Notify

Customer notification within SLA windows, including timeline, scope, and remediation guidance.

Learn

Post-incident review, code hardening, and instrumentation upgrades shipped back into production inside two sprints.

OrgX — Proof for AI-Delivered Work