Policy, evidence, and the documents behind them.
Everything governing how OrcaRouter handles your data, what our controls enforce at request time, and how to reach us about security — each claim linked to the document that backs it.
Certifications and commitments
Independent audits of our security and privacy programme, plus the contractual instruments that carry coverage where no certification exists. Reports and certificates are available to customers and prospects under NDA.
The documents
The binding agreements between you and the operating entity. Each carries its own effective date and version history.
Where your requests run
A workspace declares its region. Compliance evidence is stamped and stored under it, and a cross-region read is refused. It does not geo-pin inference: upstream providers process requests in their own regions, listed in the subprocessor table.
- Singapore
- United States
- Japan
What happens to your content
How request content and account data move through the platform.
Framework coverage
Regulatory frameworks our compliance engine maps to enforceable policy, with per-control citations to the authoritative source text.
- HIPAA Security & Privacy Rule
- PCI DSS 4.0
- EU General Data Protection Regulation
- AICPA SOC 2 Trust Services Criteria
- EU Artificial Intelligence Act
- NIST AI Risk Management Framework 1.0
- OWASP Top 10 for LLM Applications
- ISO/IEC 27001:2022 Information Security
- ISO/IEC 42001:2023 AI Management System
- PIPL + Interim Measures for Generative AI
- CCPA / CPRA
- UK GDPR + Data Protection Act 2018
- APPI (Act on the Protection of Personal Information)
- PIPA (Personal Information Protection Act)
- LGPD (Lei Geral de Proteção de Dados)
- PIPEDA + Quebec Law 25
- Digital Personal Data Protection Act 2023
- Privacy Act 1988 + Australian Privacy Principles
- Personal Data Protection Act (Singapore)
- Virginia Consumer Data Protection Act
- Colorado Privacy Act
- Connecticut Data Privacy Act
- Utah Consumer Privacy Act
- Texas Data Privacy and Security Act
- Digital Operational Resilience Act
- Gramm-Leach-Bliley Act
- NIST SP 800-53 Rev. 5 / FedRAMP
- CMMC 2.0
- HITRUST CSF v11
- FERPA
- COPPA Rule
- Colorado AI Act (SB 26-189)
These are frameworks the OrcaRouter compliance engine maps to policy and evidence. Listing one here describes a product capability, not an audit — the certifications and attestations we do hold are named under Certifications and commitments above, and the reports are available under NDA.
Report a vulnerability
If you have found a security issue in OrcaRouter, we want to hear about it.
- security@orcarouter.ai
- /.well-known/security.txt