Overview
Orchestra runs autonomous AI agents that can read and act on your business data. We designed the platform so that you stay in control of where your data lives, what your agents can touch, and which actions require your approval. This page summarises the technical and organisational measures we apply. For the full legal detail, see our Privacy Policy and Data Processing Agreement.
In short: your data is hosted in the European Union, credentials are encrypted, each customer runs in an isolated environment, every integration is limited to the minimum permissions you grant, and high-impact actions can require human approval before they run.
Data residency — hosted in the EU
All Orchestra infrastructure runs on Railway in the European Union (Amsterdam, Netherlands region): the web application, the backend API, the shared database, and each customer's dedicated agent instance together with its storage volume.
Customer data at rest is stored within the European Union. We do not use any external database (such as Supabase, Neon, or AWS RDS) or external object/file storage (such as Amazon S3 or Cloudflare R2). Everything we store resides on our EU infrastructure.
As an AI platform, Orchestra forwards content at runtime to AI model providers and to the tools you connect; some of these are located outside the EU and are governed by Data Processing Agreements and transfer safeguards. For customers who require it, an EU-only processing configuration is available (see "Compliance" below).
Tenant isolation
Every customer's AI agent runs in its own dedicated, isolated instance with its own dedicated storage volume. Customer environments are separated from one another — one tenant's agents and data cannot reach another tenant's.
Each instance authenticates to the platform with its own per-instance secret. A compromised or misbehaving instance cannot impersonate another instance or access the shared platform credentials.
Encryption
All traffic to and between Orchestra services is encrypted in transit using HTTPS/TLS.
Sensitive credentials — third-party API keys, OAuth refresh tokens, and messaging tokens — are encrypted at rest at the application layer using AES-256 before they are written to the database.
Platform-level provider keys (for example, keys we supply for transcription, search, or trial AI access) are held server-side and are never exposed to customer instances.
Least-privilege integrations — you control what agents can do
This is the core of our answer to the most common concern about AI agents: "what stops the agent from doing something destructive?"
For each integration you connect (Gmail, Google Drive, Slack, CRMs, and others), you choose an access level. Orchestra classifies every available tool for that integration as read, write, or delete, and then requests only the minimum OAuth permissions ("scopes") that your chosen access level requires.
Because the scopes are aligned to least privilege, the boundary is enforced by the provider itself — not merely by Orchestra. If you grant an integration read-only access, the agent physically cannot perform write or delete operations against that service, because the underlying credential was never granted those permissions.
You can review and revoke any integration at any time. Revoking a connection immediately removes the agent's ability to act on that service.
Human-in-the-loop approvals
Agents and automated workflows can be configured so that high-impact steps pause and wait for explicit human approval before they execute. Pending actions surface as approval gates that a person must approve or reject.
Command execution is likewise governed by an approval mechanism, so sensitive operations do not run unattended unless you have chosen to allow them. This lets you adopt automation incrementally — starting with review-before-act, and widening autonomy only where you are comfortable.
How we handle your content
We do not sell your data. We do not use your data or your agents' content to train our own models. We do not use cross-site advertising trackers or build advertising profiles.
Our shared central systems do not retain the content of your agents' conversations; that working data lives on your dedicated EU instance so your agents have the context they need to function.
Because Orchestra is an AI platform, delivering AI features requires transmitting content at runtime to the relevant model providers and connected tools. Where Orchestra supplies the provider key, that provider is a sub-processor listed in our Privacy Policy; where you supply your own key, calls are made directly under your own account and the provider's terms.
Secrets and credential safety
Credentials you provide are encrypted at rest and are used only to operate the Service on your behalf. Third-party access is scoped to the least privilege required (see "Least-privilege integrations" above).
AI agents can be exposed to untrusted input (for example, the contents of an email or a web page), which in any agentic system carries a risk of prompt-injection attempts. We mitigate this with least-privilege scoping, human-in-the-loop approvals for sensitive actions, and tenant isolation, and we recommend that you grant agents only the access levels they genuinely need. No agent platform can claim complete immunity to prompt injection, and we do not; our model is to constrain what an agent is able to do rather than to assume every input is safe.
Data subject rights and deletion
You can request access to, correction of, export of, or deletion of your personal data at any time by contacting legal@hiorchestra.com. We respond within 30 days.
When your account or instance is deleted, the dedicated instance and its storage volume are decommissioned and the associated data is deleted within 30 days, subject to any legal retention obligations. Connected integrations can be revoked individually at any time from your account.
Breach notification
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify affected users and, where required, the competent supervisory authority without undue delay and in any case within 72 hours of becoming aware of the breach, in line with GDPR Article 33.
Sub-processors and international transfers
A complete, itemised list of our sub-processors — distinguishing those Orchestra supplies from those you connect yourself — is maintained in Section 7 of our Privacy Policy, together with each one's location and transfer safeguard.
International transfers to non-EU sub-processors rely on the European Commission's Standard Contractual Clauses (SCCs), the EU–US Data Privacy Framework where applicable, and the sub-processors' Data Processing Agreements. A DPA is available to customers who require one.
Compliance
Orchestra is designed to be GDPR-aligned: EU data residency, a Data Processing Agreement offered under Article 28, defined data subject rights and retention, 72-hour breach notification, and an optional EU-only processing configuration for customers who cannot permit any processing outside the EU.
Orchestra is not currently certified under SOC 2 or ISO 27001. Enterprise customers with specific certification, audit, or data-residency requirements are welcome to contact us to discuss their needs and our roadmap.
Reporting a security issue
If you believe you have found a security vulnerability in Orchestra, please report it to security@hiorchestra.com. We appreciate responsible disclosure and will work with you to validate and address legitimate issues promptly. Please do not publicly disclose an issue before we have had a reasonable opportunity to remediate it.