Security
An AI workforce needs guardrails a normal SaaS tool doesn't. Here's exactly what Orlixa does today — and what we're honest about not having yet.
What's actually built
Every company is a separate tenant. Data, AI Employees, workflows and knowledge are scoped to your workspace and never shared across tenants.
Users are assigned roles that govern what they can see and do, enforced on every request — not just hidden in the UI.
Actions the platform considers high-risk — moving money, publishing content publicly — are automatically routed to an Approval Center. A human approves, rejects, or modifies before anything executes.
Connected-account credentials and other sensitive fields are encrypted at rest (AES-GCM), never stored or returned as plaintext.
Every skill execution and approval decision is logged, so you can see exactly what an AI Employee did, when, and who approved it.
Outbound calls to connected tools run behind rate limiting and circuit breakers, so a failing third party degrades gracefully instead of taking your workspace down with it.
Capability vs. certification
A security capability is something the product actually does — like routing a payment action through human approval. A certification is an independent audit confirming a set of controls. We don't claim a certification we don't hold.
Not yet. Formal third-party compliance certification is on our roadmap. If your organization requires it before purchase, contact sales — we’ll walk through our current architecture and timeline.
In the region your deployment is provisioned in. Enterprise plans support private/VPC deployment for organizations with residency requirements — contact sales to discuss your setup.
No. Every skill execution is recorded in an audit log, and anything flagged high-risk stops for a named human to approve before it runs.
Talk to our team about deployment options, data residency, and our security roadmap.