Google Cloud Platform
Hosted on GCP in the US with ISO 27001 certification
Your voice data is sensitive. Here's exactly how we protect it.
Hosted on GCP in the US with ISO 27001 certification
Data encrypted at rest and in transit with TLS
Full data subject rights, DPA available on request
Orai runs on cloud infrastructure in the United States. Data at rest is encrypted, data in transit is protected by TLS, and production, staging, and development environments are separated.
Practice recordings are processed to generate your feedback scores and then retained only as long as you choose to keep them. You can delete recordings from within the app.
Internal access to production systems follows the principle of least privilege. Access is reviewed regularly and revoked on offboarding.
We run dependency scanning and static analysis on code changes, monitor infrastructure, and patch critical findings promptly.
We maintain an incident response plan with severity levels, escalation paths, and communication timelines for major events.
Found something? Email security@orai.com with a description of the issue. We respond to security reports within one business day.