Trust & Security

Evidence of control, not assurances

Orchevo is built for oversight functions — security, audit and compliance — who need to verify how AI behaves, not take it on faith. Every action a person, event or agent takes is governed by one set of controls, and every action leaves an audit-grade trace. Nothing leaves the boundary you choose.

0Bytes of citizen or PII data leave your perimeter
99.9%Production uptime SLA, 24×7
90 daysMinimum immutable audit retention
100%Error traces captured, sampled on success

Governance & compliance alignment

Governance is a product capability, not a document. It is aligned to the frameworks our customers are held to.

MeitY guidelines ISO standards EU AI Act — explainability & agent cards NIST AI RMF DPDP Act ready OWASP Top 10
On certification: Orchevo's governance is aligned to the standards above and DPDP-ready by design. A formal ISO 27001 certification programme is in progress; this page states alignment honestly and will be updated as certifications are awarded.

How the platform protects data and agents

Controls apply at four enforcement points — Studio, orchestration, the AI gateway, and the data plane.

Zero data egress

Runs entirely inside your boundary — on-premises, private VPC, hybrid, air-gapped, or the Sovereign AI Box. No cloud dependency required.

Encryption at rest

AES-256 for all secrets and sensitive fields, or integrate your own secrets vault. Short-lived, scoped credentials for every tool call.

Enterprise authentication

SSO with RBAC and ABAC, short-lived JWT sessions, and MFA enforced in production. Identity travels with every request into retrieval and tools.

Permission-aware retrieval

The caller's entitlements are pushed into the index — agents surface only what their user could open in the source system. Every answer carries a citation.

Three-layer guardrails

Input rails at the gateway, runtime policy checks, and an output governance proxy — PII detection and redaction, prompt-injection defence, topic restriction, content safety and source grounding.

Safety in the runtime

Sandboxed execution, explicit egress and spend limits, and confidential computing for data in use. Whatever an injected prompt tries, the runtime cannot exceed approved permissions.

Immutable audit & lineage

Every prompt, retrieval, tool call and human decision logged in-perimeter, with data lineage from any output back to its sources and instant agent revocation.

Supply-chain integrity

Signed images and SBOMs for everything entering the registry; zero critical or high CVEs before go-live; default-deny network policies.

Full traceability

OpenTelemetry traces stitch user → agent → tool → gateway → inference → GPU in one drill-down, with cost per agent, per tenant, per GPU.

Data residency

Classification at ingestion maps content to residency zones; no citizen or PII data crosses the deployment boundary.

Bring your security team to the evaluation.

We'll walk your architecture, share the reference security model, and answer the questions oversight functions ask first.

Talk to us