Security & Governance
Governed by default, not by upgrade: granular RBAC, SSO, and a full audit log.
Architecture overview
Orvanta's architecture ensures complete separation between control plane and data plane. Every script executes in an isolated sandbox.
Encryption at rest
All databases, secret stores, and object storage volumes are encrypted at rest using AES-256 block-level encryption.
Encryption in transit
All network traffic between internal microservices and external clients is secured with TLS 1.3.
Role-Based Access Control
Fine-grained permissions model supporting exact organisational structures.
- Manage users
- Configure SSO
- All permissions
- Write scripts
- Deploy flows
- View secrets
- Execute flows
- View logs
- Publish apps
- View runs
- Read audits
- View settings
- Mix permissions
- Group mapping
- API access
Audit logging
Every state-changing action is securely logged with immutable timestamp, user, and payload data.
Container isolation
- • Dedicated sandbox per execution
- • Temporary filesystem cleared on exit
- • Memory and CPU limits enforced via cgroups
- • No shared state between parallel runs
- • Strict 360-second execution timeout
Multi-tenancy
Data is strictly isolated at the workspace level. Database rows, object storage, and secrets are tied to specific workspace IDs.
Zitadel SSO & SAML
Enterprise identity management integrated out of the box.
- • SAML 2.0 and OIDC support
- • Automatic SCIM user provisioning
- • Just-in-Time (JIT) account creation
- • Group claim synchronization
Compliance roadmap
Plainly, so procurement can plan around it: “In progress” means readiness work. We are establishing the scope, controls and evidence each standard requires, together with prospective customers and their legal teams. It does not mean an audit is running. No SOC 2 Type II audit has been completed, no ISO 27001 certificate has been issued, and there is no report or certificate we can send you today. We will publish a target window here once one is committed to. GDPR is a self-assessed legal position rather than a third-party attestation, set out in our privacy policy.
Responsible disclosure
We take security seriously. If you believe you have found a vulnerability, please contact us immediately.
security@orvanta.cloud