Security and isolation

Security and access boundaries

Reference Updated 2026-09-26

Orneos is pre-release. This page describes current boundaries, not a security certification or an uptime guarantee.

Access to work

Sign-in and authorized company/team access determine which work you may use. Membership and Vault access have distinct rules; see Members and roles and Vault spaces. Company-admin status alone does not grant team roster administration.

Data on your device

The app stores part of your working data locally. Removing access can prevent future authorized requests, but cannot guarantee erasure of data previously received, copied or exported. Use a trusted device and review Local data and storage before clearing data or sharing a browser profile.

Credentials and assurance

Protect your account and any provider keys. Read AI keys for the browser-held drafting-key boundary and Privacy and your data for handling details. Do not assume SOC 2 certification, enterprise SSO, a published SLA or production-scale assurance from this documentation.

Discuss your security requirements with us before sharing sensitive material. The detailed edition supports a closer technical evaluation.

Something here wrong, missing or out of date? Tell us at support@orneos.com — corrections to these pages are welcome and we would rather hear it than have you work around it.