Security
Last updated June 15, 2026
Data Access & Permissions
Orloi follows a least-privilege approach for integrations. The changelog engine uses the connected Airtable base, selected scope, linked accounts, and customer-configured Postgres destination needed to operate the service. We do not intentionally capture Airtable data outside the connected base and explicit scope you configure.
Systems and personnel are granted only the minimum access required to operate the service.
Data Storage & Retention
We store account information, connection configuration, encrypted service-managed credentials, and operational logs required to operate the service.
For the changelog engine, Airtable activity may include record values, previous values, schema changes, actor or source metadata, and derived operational summaries for the configured scope. Raw events, compacted events, metrics, reports, and other derived outputs are written to the customer-configured Postgres storage in the dedicated orloi schema.
The customer-configured Postgres destination is the durable system of record for Orloi output. Customers control retention, deletion, backups, restoration, and read access for their own Postgres storage unless a separate managed-deletion workflow is agreed.
Operational logs and transient processing data are retained only as needed to support delivery, retries, troubleshooting, security, and service reliability.
Encrypted backups of Orloi-managed application data may be retained for disaster recovery purposes.
Hosting & Infrastructure
Orloi's primary application server is hosted in the EU. Application configuration, account data, encrypted credentials, task state, and operational metadata are stored in Supabase in the EU.
Orloi uses serverless Redis for caching, deduplication, debounce, distributed locking, and operational coordination. This cache is treated as ephemeral operational state and is not the durable store for raw changelog records.
Credentials & Secrets
Service-managed OAuth tokens, API credentials, and customer-provided changelog storage connection strings are encrypted before being stored by Orloi.
Credentials managed directly by Orloi are encrypted with AES-256-GCM using application-managed key material. Customer-controlled Postgres storage and any read-only agent or BI access are secured according to the customer's database configuration and provider controls.
All network communication with the service is encrypted in transit via HTTPS/TLS.
AI Processing
AI is not required for the core changelog. When AI features are enabled, Orloi uses bounded operational context such as compacted events, schema context, metrics, and report bundles to generate reports, summaries, and interpretation.
Personal details such as emails and phone numbers are pseudonymized before LLM processing paths that support AI summaries and analysis.
Raw events are reserved for provenance, debugging, audit reconstruction, and recomputation. They are not the default input for AI reports.
Reliability & Failure Modes
Orloi only starts capture after the Postgres destination has been installed and verified. If Airtable, Postgres, AI providers, or other third-party services are unavailable, capture, processing, or report generation may be delayed or retried. We avoid silent data loss; failures are surfaced and retried when possible.
Access Control & Operations
Production access is limited to minimum personnel. Direct human access to customer data is minimized and reserved for support and incident resolution.
Administrative access to production systems is protected by two-factor authentication (2FA).
Deletion & Exit
You can disconnect integrations from product settings or from the provider side. Disconnecting stops future capture and removes or disables the related Orloi-managed connection records according to the relevant lifecycle, subject to operational and legal requirements.
For the changelog engine, disconnecting does not automatically delete data already written to customer-controlled Postgres storage.
Deletion and retention policies are described in more detail in our Privacy Policy.
Compliance Documents
Orloi publishes its Privacy Policy, Terms of Service, Data Processing Agreement, Subprocessor List, Records of Processing Activities, and Retention Policy in the Trust Center.
Active subprocessors are reviewed and listed with their purpose, role, processing location, and available privacy or security documentation.
Incident Response
In the event of a security incident involving personal data, we follow documented response procedures, including investigation, mitigation, and notification in accordance with applicable data protection laws.
Security Contact
Report security concerns to security@orloi.ai.