Skip to content
Orlenn
Security

Security & trust

Orlenn is built to run on public-facing sites and inside businesses that care about their data.

01

Your keys (BYOK)

Every tenant supplies its own model key; there is no platform key at runtime.

02

Encryption

Integration secrets are stored AES-256-GCM encrypted.

03

Access control

Dynamic role-based permissions, deny-by-default for custom roles, and mandatory 2FA (TOTP).

04

Tenant isolation

Every record and credential is scoped to its tenant; tools can't leak across tenants.

05

Safe by default

Prompt-injection defense, idempotent actions, per-conversation token budgets, and rate limiting on public endpoints.

06

Auditability

An immutable log records every tool execution and admin action.

Roles & permissions
Role-based access control in Orlenn
Immutable audit log
The Orlenn audit log
Bring your own model key
BYOK settings
For your security team

We're happy to walk through our controls in detail — reach out and we'll set up a review.