Skip to main content
ORGAOrganized Data GovernanceDiscuss a pilot
Menu

Governance & security

Trust begins with an accurate account of the system.

ORGA’s posture is to define boundaries plainly, document what is implemented, and put unresolved responsibilities into the client architecture and agreement before sensitive data is introduced.

Current maturity statement. ORGA does not claim SOC 2, ISO 27001, HIPAA certification, penetration testing, an uptime guarantee, or a universal data-residency posture. The current product repository also requires a dedicated client data environment before any external-client or sensitive production data is onboarded.

What is established, and what must be confirmed.

Authentication and access

The application supports individual authentication, active organization membership, and role-based access. Final identity requirements, including MFA or SSO, must be confirmed per engagement.

Implemented foundation; scope-specific confirmation

Data encryption

Production vendors generally provide encryption capabilities, but ORGA has not published a client-specific encryption standard or key-management commitment.

Pre-contract technical confirmation required

KPI lineage and audit history

The product model supports definitions, source relationships, validation records, and audit events. Durable audit scope and retention must be defined for each client.

Implemented model; retention not publicly committed

Freshness and validation

KPIs can carry refresh expectations, source references, validation dates, and status. Client owners remain responsible for approving business definitions.

Defined in application architecture

Backups and recovery

No public recovery-time, recovery-point, or tested-restore commitment is made. Backup provider, schedule, retention, and restoration testing belong in the client architecture.

Pre-contract decision required

Hosting and data residency

Hosting region, vendor, environment separation, and residency requirements are selected and documented for the engagement. ORGA makes no blanket residency claim.

Pre-contract decision required

AI providers and model data handling

Approved providers, model endpoints, retention settings, and what context may be sent are documented before AI-assisted features are enabled.

Provider-specific review required

External model training

ORGA does not promise a universal answer across providers. The contract and selected provider settings must expressly state whether customer data can be used for training.

Must be prohibited or disclosed in contract

Logging and incident response

Security-relevant logging and response responsibilities are scoped per client. ORGA does not claim a certified or independently audited incident-response program.

Operating procedure must be confirmed

Ownership and source code

The intended model is a client-owned application. Exact ownership of code, reusable ORGA components, infrastructure, credentials, and third-party licenses must be stated in the agreement.

Contract language Kyle must confirm

Portability and offboarding

Data export, credential transfer, repository access, transition support, deletion, and retention should be explicit before work begins.

Contract language Kyle must confirm

ORGA maintenance

ORGA’s maintenance responsibilities may include integrations, application updates, monitoring, security work, and AI evaluation only as specified in the service agreement.

Scope-specific service terms required

Built for one business. Governed with that business.

Clients control the business data, definitions, users, and permission decisions in their application. ORGA maintains the system within written responsibilities.

Before a pilot moves beyond illustrative or non-sensitive data, both parties should approve the data inventory, role model, provider list, access process, recovery posture, AI handling rules, and offboarding plan.

Executive intelligence pilot

Define the trust boundary before the build.

Begin with the executive team, the decisions that matter most, and a clear definition of success.

Discuss an executive intelligence pilot