01 · What this policy covers

Topics addressed in this policy

  • Security program overview at a non-sensitive level
  • Application, infrastructure, and access-control themes ORCA can disclose
  • Data protection practices relevant to website and customer integrations
  • Vulnerability reporting contact and process
  • Subprocessors or infrastructure statements approved for publication
  • Certifications or audit reports only when verified

Page: Security

Required sections

Required sections for security and counsel

1. Security program overview at a non-sensitive level 2. Application, infrastructure, and access-control themes ORCA can disclose 3. Data protection practices relevant to website and customer integrations 4. Vulnerability reporting contact and process 5. Subprocessors or infrastructure statements approved for publication 6. Certifications or audit reports only when verified

Website product notes

---

  • Site hosting preference is Cloudflare Pages
  • Form handling preference is Cloudflare Worker plus Turnstile
  • Do not claim SOC 2, ISO, or other certifications unless independently verified for ORCA

Next step

Questions about these policies?

For privacy or legal requests, contact the ORCA team once an approved path is published.