Authentication and access
The application supports individual authentication, active organization membership, and role-based access. Final identity requirements, including MFA or SSO, must be confirmed per engagement.
Implemented foundation; scope-specific confirmationData encryption
Production vendors generally provide encryption capabilities, but ORGA has not published a client-specific encryption standard or key-management commitment.
Pre-contract technical confirmation requiredKPI lineage and audit history
The product model supports definitions, source relationships, validation records, and audit events. Durable audit scope and retention must be defined for each client.
Implemented model; retention not publicly committedFreshness and validation
KPIs can carry refresh expectations, source references, validation dates, and status. Client owners remain responsible for approving business definitions.
Defined in application architectureBackups and recovery
No public recovery-time, recovery-point, or tested-restore commitment is made. Backup provider, schedule, retention, and restoration testing belong in the client architecture.
Pre-contract decision requiredHosting and data residency
Hosting region, vendor, environment separation, and residency requirements are selected and documented for the engagement. ORGA makes no blanket residency claim.
Pre-contract decision requiredAI providers and model data handling
Approved providers, model endpoints, retention settings, and what context may be sent are documented before AI-assisted features are enabled.
Provider-specific review requiredExternal model training
ORGA does not promise a universal answer across providers. The contract and selected provider settings must expressly state whether customer data can be used for training.
Must be prohibited or disclosed in contractLogging and incident response
Security-relevant logging and response responsibilities are scoped per client. ORGA does not claim a certified or independently audited incident-response program.
Operating procedure must be confirmedOwnership and source code
The intended model is a client-owned application. Exact ownership of code, reusable ORGA components, infrastructure, credentials, and third-party licenses must be stated in the agreement.
Contract language Kyle must confirmPortability and offboarding
Data export, credential transfer, repository access, transition support, deletion, and retention should be explicit before work begins.
Contract language Kyle must confirmORGA maintenance
ORGA’s maintenance responsibilities may include integrations, application updates, monitoring, security work, and AI evaluation only as specified in the service agreement.
Scope-specific service terms required