Security & privacy
What we actually do with your calls.
Your calls contain your customers' personal information. This page describes how we handle it — as engineering practice and policy, not as a badge we haven't earned.
We hold no security certifications. Read that first.
ORENIQ is an early-stage company. We are not SOC 2 audited, ISO 27001 certified, HIPAA-attested, or PCI compliant, and we hold no third-party security attestation of any kind. No auditor has verified anything on this page.
Everything below is a description of what we do, given in good faith so you can assess us on the substance. If your procurement process requires a formal report today, we are not the right supplier yet — and we would rather tell you that here than waste a month of your time discovering it.
Our practices
How the system is built.
Each of these describes something in place today. None of it is aspirational.
Encryption in transit and at rest
Call audio, transcripts, and customer records travel over TLS and are stored encrypted at rest by our infrastructure providers. Internal service traffic is encrypted too.
Credentials stay scoped
Calendar and CRM connections use OAuth tokens or scoped API keys held in a managed secrets store — never in source control, and never in plain text in our logs. We request the narrowest scope that makes the integration work.
Least-privilege access
Access to production data is limited to the people who need it to operate the service, is individually attributed, and is revoked when someone changes role or leaves.
Your data stays yours
We do not sell customer data, share it with advertisers, or use your call recordings to train third-party foundation models. It is processed to deliver the service you bought.
Deletion on request
You can ask us to delete call recordings, transcripts, or an entire account. We act on deletion requests and confirm when they're complete; backups age out on their retention cycle.
Call recording disclosure
Recording and AI-handling disclosure is built into the greeting, because in many places consent is a legal requirement rather than a nicety. You control the exact wording.
Human escalation as a safety valve
Every deployment has defined conditions — urgency, distress, explicit request — that hand the call to a person. The AI is never the last resort on a call that needs one.
Subprocessors are disclosed
Telephony, speech, language model, and hosting providers each process data on our behalf. We name them on request and in our data processing information.
Limitations
What we don't do, and won't pretend to.
Most vendors leave you to infer this from silence. We'd rather write it down.
We hold no compliance certifications yet
ORENIQ is an early-stage company. We are not SOC 2 audited, ISO 27001 certified, or HIPAA-attested, and we will not claim otherwise. If your procurement process requires a formal attestation, we are not the right supplier today — tell us and we'll say so directly.
Not for protected health information
Do not configure ORENIQ to collect clinical detail or protected health information. Our healthcare-adjacent deployments handle scheduling and general enquiries only.
Not for payment card data
The receptionist will not take card numbers, CVVs, or bank details over the phone. Payment collection belongs in a PCI-compliant flow we don't operate.
Data handling
What we collect, and for how long.
Some values below still need confirming for our operating setup — they're marked, rather than guessed at.
- What we collect from a call
- Caller number, call audio, the transcript, structured fields the caller provides (name, contact details, reason for calling), and the outcome. [CONFIRM: whether you retain raw audio or transcript only.]
- How long we keep it
- [PLACEHOLDER: confirm your retention period — e.g. recordings 30 days, transcripts 12 months.] Retention is configurable per account, and shorter windows are available on request.
- Where it's processed
- [PLACEHOLDER: confirm hosting and processing regions, and whether data crosses borders.] Region pinning is available where our providers support it.
- Who else touches it
- Telephony, speech-to-text, language model, and hosting subprocessors, each under contract and only to deliver the service. [PLACEHOLDER: list the specific providers you use.]
- Reporting a vulnerability
- Email us with details and we will acknowledge receipt. Please give us a reasonable window to fix an issue before disclosing it publicly. We do not currently run a paid bug bounty.
Questions we haven't answered here, a security review to run, or a vulnerability to report? Email hello@oreniq.in. We'll give you a direct answer, including when the answer is “we don't do that yet”.
Still want to see it work?
Bring your security questions to the demo call. We'd rather field the hard ones early.