Security

Built for enterprise control, not just enterprise scale

An AI workforce needs guardrails a normal SaaS tool doesn't. Here's exactly what Orlixa does today — and what we're honest about not having yet.

What's actually built

Security capabilities

Tenant isolation

Every company is a separate tenant. Data, AI Employees, workflows and knowledge are scoped to your workspace and never shared across tenants.

Role-based access control

Users are assigned roles that govern what they can see and do, enforced on every request — not just hidden in the UI.

Human approval on risky actions

Actions the platform considers high-risk — moving money, publishing content publicly — are automatically routed to an Approval Center. A human approves, rejects, or modifies before anything executes.

Encrypted credentials

Connected-account credentials and other sensitive fields are encrypted at rest (AES-GCM), never stored or returned as plaintext.

Full audit trail

Every skill execution and approval decision is logged, so you can see exactly what an AI Employee did, when, and who approved it.

Resilient by design

Outbound calls to connected tools run behind rate limiting and circuit breakers, so a failing third party degrades gracefully instead of taking your workspace down with it.

Capability vs. certification

We distinguish the two on purpose

A security capability is something the product actually does — like routing a payment action through human approval. A certification is an independent audit confirming a set of controls. We don't claim a certification we don't hold.

  • Tenant isolation — capability, implemented
  • Role-based access control — capability, implemented
  • Human approval on high-risk actions — capability, implemented
  • Encrypted credentials at rest — capability, implemented
  • SOC 2 / ISO 27001 — certification, not yet held

Security FAQ

Is Orlixa SOC 2 or ISO 27001 certified?

Not yet. Formal third-party compliance certification is on our roadmap. If your organization requires it before purchase, contact sales — we’ll walk through our current architecture and timeline.

Where is my data stored?

In the region your deployment is provisioned in. Enterprise plans support private/VPC deployment for organizations with residency requirements — contact sales to discuss your setup.

Can an AI Employee take an action without anyone knowing?

No. Every skill execution is recorded in an audit log, and anything flagged high-risk stops for a named human to approve before it runs.

Need a security review for procurement?

Talk to our team about deployment options, data residency, and our security roadmap.