Built for sensitive business data
Oren AI is used by small and mid-sized businesses to run real workflows on top of real customer data. That information is sensitive, so we treat security as part of the product, not an afterthought.
Access and identity
Every account requires verified email plus password authentication. Sensitive workflows are additionally gated by a PIN system tied to server-side sessions.
Authorization is enforced server-side. A user signed into one organization cannot reach another's data.
- Industry-standard password hashing
- Mandatory email verification
- PIN-gated sessions for sensitive flows
- Hardened session cookies
How your data is stored and protected
Customer data and documents are stored on managed, enterprise-grade infrastructure. Encrypted in transit. Encrypted at rest.
Encrypted in transit
All traffic is served over HTTPS. Insecure connections are refused.
Encrypted at rest
Customer data is encrypted at rest with industry-standard managed keys.
Uploads are validated
Files are inspected at the binary level before they touch storage. Disguised or malformed content does not get in.
Secrets are handled securely
Secrets are encrypted at rest and access-controlled by role. They are not exposed in plaintext in logs or interfaces.
Where your data lives
Oren AI runs in a single US region. Customer data and backups stay in-region.
The company itself is Canadian (Montreal, Quebec) and operates under PIPEDA and the Quebec Privacy Act. See our Privacy Policy for details on cross-border processing.
Your data is not used to train models
Oren AI does not train models on customer prompts, documents, or workspace data. Our AI providers are contractually bound not to train on submitted data either.
Provider responses are used only to deliver the feature you invoked.
Per-organization isolation
Every record is scoped to the organization that owns it, and authorization is enforced server-side on every request. IDs are not a security boundary; permissions are.
Public-facing endpoints carry an additional token-plus-PIN gate, verified server-side before any data is read.
Protected infrastructure
Oren AI runs on isolated, managed infrastructure with TLS terminated at the edge. Every response ships with a modern set of browser security headers:
- Strict transport security
- Content security and frame policies against clickjacking and injection
- MIME-sniffing protection
- Restricted referrer policy
- Restricted browser permissions
No database or admin interface is exposed to the public internet. Internal traffic stays inside a private boundary.
Logging and monitoring
Authentication events, uploads, and administrative actions are logged with attribution and retained for operational use.
Raw document contents and other sensitive payloads are never logged.
Third parties we rely on
A small set of sub-processors operate the service. Each is bound by their own data protection terms and given only what they need:
- Cloud infrastructure and storage
- LLM inference
- Billing and payments
- Transactional email
Named list and DPA available on request to johnny@johnnychen.co.
Compliance posture
Oren AI is operated by 11893874 CANADA INC., a Quebec-based company. Our privacy program is built on PIPEDA and the Quebec Privacy Act (Law 25). SOC 2 attestation is in progress, and we will publish our progress here as it advances.
Frequently asked questions
Where is my data stored?
Application data, documents, and account records are stored with a tier-1 cloud provider in a single US region. Backups stay within the same region.
Is my data used to train AI models?
No. Oren AI does not train models on customer data, and our AI providers contractually agree not to train on data submitted through their APIs.
How are organizations isolated from each other?
All records are scoped to the organization that owns them. Authorization is enforced server-side on every request, so a user in one organization cannot access data belonging to another.
Who are your sub-processors?
We rely on a tier-1 cloud provider for hosting and storage, commercial LLM providers for inference, a payments processor for billing, and a transactional email service. A full named list is available under NDA on request.
How is data encrypted?
All traffic is encrypted in transit with TLS and HSTS. Customer data is encrypted at rest using industry-standard managed keys.
How are secrets and API keys managed?
Secrets are encrypted at rest and access-controlled by role. They are never written to source control or application logs.
Do you support SSO (SAML / OIDC) or SCIM?
Not yet. Today, accounts use email and password with mandatory email verification. SSO and SCIM are on the roadmap for enterprise customers. Reach out if this is a requirement.
Are you SOC 2 or ISO 27001 certified?
Not currently. SOC 2 Type I is in progress. In the meantime, we can share a security questionnaire response and our DPA on request.
How do I report a security issue?
Email johnny@johnnychen.co with the subject line "Security". We acknowledge reports within two business days.
What happens to my data if I cancel?
Customer data is available for export for thirty days after cancellation, then deleted from active systems. Backups roll off within ninety days. Full details are in our Privacy Policy.
Have a security question?
Whether you are evaluating Oren AI for your team or reporting a vulnerability, we want to hear from you.
johnny@johnnychen.co