Orchard← Back to site

Security & data handling

Evaluation overview · the binding terms live in the DPA

Understand work. Control what is monitored.

A plain-English overview for security and IT leaders evaluating Orchard — what we monitor, how capture settings affect collection, and how access to your data is controlled.

Overview for evaluation · the binding terms live in our Data Processing Agreement.

  • 0 screenshots or raw keystroke logging in monitoring capture
  • Fail-closed tenant isolation — no context, no rows
  • Every read by our staff is audit-logged
  • You own it — your data, deletable on request

The capture boundary

Monitoring scope is controlled by your organization. Supported capture settings determine the activity and content collected; recognized password fields are excluded.

What Orchard records

Depending on the monitoring scope and capture settings you enable.

  • Foreground application in focus
  • Window title of the active window
  • Active vs. idle time
  • On-screen control type & label (e.g. "Button — Save")
  • Committed field values and interactions when full capture or work recording is enabled
  • Clipboard text in captured copy/paste actions when full capture or work recording is enabled; recognized password fields are excluded
  • Network flow metadata — application, remote address and port, connection counts; never payload contents
  • Voice transcripts only on a workspace holding the Technician module, and only on your own staff's endpoints; see Section 5.2 of the DPA
  • Endpoint health — hardware, OS, heartbeat

Excluded from monitoring capture

These limits apply to the supported monitoring capture settings.

  • No screenshots or screen images
  • No raw keystroke logging — committed field values may be captured as described above
  • Recognized password fields — controls identified as password fields by the application or browser are skipped; credential capture is not a supported monitoring setting

Orchard records activity and, when enabled, the content and interactions needed to understand and automate work. It does not collect screenshots or raw keystroke logs through monitoring capture.

Choose scope with content in mind

Full capture can include field values and clipboard content outside a manually started recording. Choose the applications, endpoints, and capture settings appropriate to your purpose.

Recognized password fields are excluded. Sensitive information entered into ordinary fields, titles, or clipboard content may still be included in enabled capture. Configure exclusions for the environments you monitor.

How your data is protected

Isolation at the database, least privilege at the edges, accountability for the one exception.

  • Tenant isolation, fail-closed. Every record is scoped to your organization and enforced in the database with PostgreSQL Row-Level Security. If a query arrives without your tenant context, it returns zero rows — never another customer's data. The default is "nothing," not "everything." Where you manage client organizations, they sit within your tenant with separate scoping and per-client automation controls. Your customer tenant remains the isolation boundary.
  • Least-privilege access. Your team's console has owner / admin / read-only roles. Agent and enrollment tokens are locked to a single tenant. Logins are rate-limited and timed uniformly to resist account-guessing.
  • Multi-factor authentication. Every operator can turn on app-based two-factor authentication (TOTP), backed by one-time recovery codes. Owners can require MFA for their whole workspace — anyone not enrolled is walked through setup before they can use the console again. On Orchard's own staff console, MFA is mandatory, not optional.
  • Our access is the audited exception. Orchard support tooling is a separate system with its own separate credentials and multi-factor authentication, on a database role that can only read tenant data. Every read it makes is written to an immutable audit log — who, what, which tenant, when. The one path that bypasses isolation is fully accountable, never silent.
  • Encrypted in transit, with nothing in the middle. Traffic between endpoints, the Orchard API, and your console is protected with current TLS that terminates on our own Google Cloud load balancer. There is no third-party edge proxy in front of it, so no vendor outside the list below decrypts a request that carries your captured content. Passwords and tokens are never written to logs.

When Orchard acts on your systems

Automation is the point — so the controls that bound it are built in, not bolted on. You hold the dial: scope what may run unattended, see everything it did, and pull one brake to stop all of it.

  • You set the autonomy ceiling. Every playbook runs under a trust dial you control. Set it to supervised and every unattended run holds its outward changes for a person to approve — regardless of what the playbook itself says. Tighten it further for an individual end-client. Whoever presses Run is always their own supervisor.
  • Irreversible steps can be gated. Orchard classifies every action as read-only, reversible, or irreversible — a sent email, a shell command, a driven desktop. Switch on the irreversible-step gate and those are held for human approval before they fire. Anything we can't prove we can undo is treated as irreversible.
  • Every action is logged — like our staff's reads. Each run, and each step it took — inputs, outputs, outcome — is recorded to a per-tenant history you can review. Operator changes land in an append-only audit trail: who, what, when. The action side is as accountable as the read side.
  • One brake stops everything. A single switch pauses all unattended automation — for your whole account, or for one end-client — instantly. Scheduled and triggered runs stop; a person keeps manual control for incident response. And when a run can be undone, the revert engine walks it back step by step and reports plainly what it could and couldn't reverse.

For a change on a machine, Orchard acts through the agent already running on that endpoint — in the machine's own signed-in session — not by holding your administrator passwords centrally. For a change in a connected app, it uses the integration credentials you chose to connect. And it never pretends to un-send an email or un-run a command: where an action can't be reversed, the product says so — and can hold it for your approval first.

Where it lives & who we rely on

A deliberately short list of vendors — fewer hands on your data.

  • Google Cloud Platform (GCP). Cloud infrastructure, the managed PostgreSQL database, the analytics store, and the load balancer every request lands on, hosted in the United States (us-central1). The database sits on a private network with no public address.
  • Cloudflare. DNS, this website, and the public downloads of the watcher installer and browser-extension updates. Not in the path of your data. Until September 2026 Cloudflare's edge terminated TLS in front of the platform; since 16 September the API, your console and the admin console resolve straight to our Google load balancer, so Cloudflare no longer decrypts — or sees — anything your endpoints send.
  • Resend. Transactional email only — things like password resets and account notices.
  • Soniox. Live call transcription, on United States endpoints, only where the Technician module is in force and only for your own staff's machines. Audio is streamed for transcription and stored by neither party; Orchard keeps the returned text. Soniox does not train its models on submitted audio. It replaces Deepgram, which is in service until 18 October 2026 while the sub-processor notice period runs. See Section 5.2 and Annex C of the DPA.
  • Your own integrations. Connections you choose to add — for example a read-only ConnectWise/PSA link — stay under your control. They are your integrations, not ours.

What you can count on

The commitments behind the architecture.

  • You decide what's monitored. You authorize the endpoints and the purpose — Orchard acts on your instructions, as your data processor.
  • We don't sell your personal data. Processing follows your instructions and our DPA, including its terms for anonymized, aggregated workflow data.
  • Monitoring has defined boundaries. Supported capture excludes screenshots, raw keystroke logging, and recognized password fields. Content in ordinary fields and clipboard actions depends on your enabled scope.
  • You can get it back or have it deleted. On request, and on termination, we return or delete your data.
  • Internal access is accountable. When our team can see tenant data at all, it is read-only and every view is logged.
  • The full detail is on paper. Our Data Processing Agreement covers processing terms, sub-processors, breach notification, and data-subject rights — available for your review.

Where we are, and what's next

We'd rather tell you our stage plainly than dress it up.

Orchard is an early-stage platform in active design-partner deployments. The protections above are how the product works today — the capture boundary is enforced in the agent, tenant isolation is enforced in the database, automation runs under the controls you just read, and every action and staff read is logged. What we haven't done yet, we won't claim. The items below are on our roadmap as we move out of the design-partner stage — not finished audits.

  • SOC 2 — we're pursuing SOC 2, beginning with the Type I foundation. Not yet audited; we'll share current status on request.
  • Independent penetration test — a third-party test is on the near-term plan; the report will be available under NDA once complete.
  • Single sign-on (SSO) — discuss OIDC sign-in configuration and availability for your organization with us. We can confirm supported providers and deployment requirements during evaluation.
  • Compliance frameworks — a DPA is available now, and Annex A of it carries the concrete retention and deletion window for every class of data we hold. A Business Associate Agreement is available; it is the document to read if any endpoint you enroll touches Protected Health Information, and it excludes call transcription outright. HIPAA has no certification to hold, and we are not certified against PCI-DSS or CJIS today. We'll tell you plainly what we can and can't meet for a given end-client rather than imply coverage we don't have.

Want to go deeper? We're glad to walk your security team through the architecture, share the full Data Processing Agreement, and answer anything this overview didn't. Ask your Orchard contact.

TrustPrivacyDPAEULAHidden DeploymentDeployment PackBAA

Orchard © 2026 · Enter the Orchard Syndicate