SECURITY

Security

AES-256 encryption. TLS 1.3 transit. SOC 2 aligned infrastructure. EU data residency.

Last Updated: April 2026

Plain English: Your data is encrypted everywhere, stored in EU data centers, and accessible only to the people who need it. We test our security continuously and fix issues fast.

Infrastructure Security

Oran runs on SOC 2 Type II compliant infrastructure with 24/7 monitoring, redundant systems, and EU data residency by default.

Data Encryption

We use AES-256 for all data at rest and TLS 1.3 for all data in transit. Your credentials for third-party integrations (CRM, Email) are stored in a dedicated, hardware-backed vault.

Access Control

We follow the principle of least privilege. Internal access to production systems is restricted to a small number of engineers and requires multi-factor authentication (MFA).

Vulnerability Management

Our codebase undergoes automated security scanning on every commit. We also conduct periodic external penetration tests to identify and remediate potential risks.

Responsible Disclosure

If you believe you've found a security vulnerability in Oran, please contact security@getoran.com.