Your data stays yours.

SOC 2 Type II certified. AES-256 at rest and in transit. No model training on customer data. GDPR and HIPAA compliant by design.

Security posture

Six pillars. Zero compromise.

Encryption

AES-256 Encryption

All data encrypted at rest and in transit. TLS 1.3 for every connection, AES-256 for every byte stored. Key management via HSM with automatic rotation.

AI policy

No AI Training

Your data is never used to train models — ours or anyone else’s. Matching happens in isolated, stateless containers that are destroyed after every session.

Audit

SOC 2 Type II

Annual audit by a Big Four firm. Full report available under NDA to Enterprise customers. Continuous monitoring, not a point-in-time snapshot.

Access

Access Control

Role-based access control with granular permissions per tender, per module. SSO via SAML 2.0 and OIDC. Multi-factor authentication enforced by default.

Residency

Data Residency

Choose where your data lives: EU (Frankfurt), US (Virginia), or APAC (Singapore). Data never leaves the region you select. Sub-processor list published and updated quarterly.

Privacy

GDPR Compliant

Data Processing Agreement included with every contract. Full sub-processor list published. Right to erasure honored within 72 hours, with cryptographic proof of deletion.

Certifications
ISO 13485/SOC 2 Type II/GDPR/HIPAA
Trust Center

Evidence on request. No black box.

SOC 2 Type II report, DPA, and sub-processor list are available to qualified prospects under NDA. Enterprise customers receive continuous-control evidence through their CSM.

Request SOC 2 reportRequest DPA / security pack

We state certified controls only where audits are complete. Ask sales for current status if you are mid-procurement questionnaire.

Your next tender
is due Friday.

Hand Orbid AI the file. Get back a submission-ready response — products matched, specs checked, evidence on every line.

Try Orbid AIBook a demo
Security & Compliance · SOC 2, HIPAA, GDPR | Orbid AI