Security at Orkindo
Updated September 7, 2026
Governance is not a feature bolted onto Orkindo, it is the core of the platform. Every connection between an agent and your data passes through a centralized, governed layer. This page describes the controls that protect your data in enough detail for a security review to score them, and it says plainly where we stand on certification.
Where your data lives
Orkindo is not a shared multi-tenant SaaS. Every customer runs on a dedicated instance:
- Its own domain
- Its own PostgreSQL database
- Its own Redis
- Its own application containers
- Its own network
Nothing is shared with another customer. The same instance can be operated by Orkindo, deployed in your own cloud account, or installed on premise in your data center. The platform ships as containers, so the deployment profile is a choice, not a separate product.
Reaching private systems
A database on a private network with no public IP is not a blocker. A secure tunnel, configured from System Settings on your instance, lets agents reach it without opening a single inbound port or exposing the database to the internet. Every database connection is tested before it can be saved, so a broken or misconfigured credential fails on the settings screen rather than in production.
Encryption
Data on the platform is protected with AES-256 encryption at rest, and connections to the platform are served over HTTPS.
Access control
Orkindo enforces access at three layers.
Roles. Roles form a nested hierarchy rather than a flat list. A user's effective permissions come from the role they are actively using in the current session, not from the union of every role they were ever assigned. More than 180 individual permissions cover every workflow, tool, database connection, knowledge collection, channel, and administrative action.
Records. Beyond role permissions, individual records carry their own allowlist of users and roles. A workflow, a database connection, or a knowledge collection can be made visible to exactly the people who should see it, and to nobody else.
Agents. Each agent reaches only the workflows, tools, databases, and knowledge collections it was explicitly granted, and permissions are enforced at the workflow level.
Multi-factor authentication
If any role assigned to a user requires multi-factor authentication, that user must enroll, without exception. Enrollment, challenges, and resets are recorded in a dedicated MFA audit log.
Agent credentials
Agents never receive an administrative credential. For every database you register, the platform provisions a SELECT-only role and connects agents through it. For object storage it provisions a user that can only list and read. An agent can answer any question about the data and cannot change a single row. Actions that must write to a system, such as creating a ticket, go through explicit tools that an administrator grants on purpose.
Sandboxed execution
Each workflow runs in its own isolated Python environment with its own dependencies. One workflow's packages cannot affect another, and no workflow runs with more access than it was granted.
Audit
The audit log records workflow changes, agent executions, data access, channel messages, human takeovers in the support desk, approvals in agent organizations, credential changes, and MFA events, each with who, what, and when. When something happens, you can reconstruct it.
Cost controls
Token budgets can be capped per team and per agent. LLM cost tracing shows every model call by workflow and by model, and usage reports break spend down by role.
Data governance and model providers
You decide which databases, documents, and tools each agent can reach, and every connection is governed by the same central layer. Orkindo supports more than 100 LLM providers, selected per workflow. Workloads with strict data requirements can run local models through Ollama, in which case no prompt, document, or query result leaves your instance. Where a hosted provider is used, you know exactly which one sees which workflow's data.
Reliability
The platform is operated for enterprise reliability, with a 99.9% uptime SLA for customers.
Compliance posture
We are not SOC 2 certified today. Our controls are designed to align with SOC 2 principles and with GDPR requirements, and we say that plainly rather than implying otherwise. Detailed security documentation, including the control set described on this page in questionnaire form, is available for procurement and legal review on request through contact@orkindo.ai.
Reporting a vulnerability
If you believe you have found a security issue in our website or platform, please write to contact@orkindo.ai. We appreciate responsible disclosure and will respond promptly.