Ora runs on enterprise-grade infrastructure, handles data with care, and is on a clear path to full compliance certification. Here's exactly what we do and where we're headed.
We believe in radical transparency. Here's our exact compliance status — the good and the in-progress.
Every Ora deployment is built on the same security architecture. Here's what's protecting your business and your customers' data.
Enterprise-grade components, all the way down.
| Component | Provider | Standard | Location |
|---|---|---|---|
| AI Model | Anthropic Claude | SOC 2 Type II, GDPR | US (data not retained) |
| Database | Supabase (PostgreSQL) | SOC 2 Type II, ISO 27001 | AWS Sydney (ap-southeast-2) |
| Hosting & Edge | Vercel | SOC 2 Type II, ISO 27001 | Global edge, AU region |
| Payments | Stripe | PCI DSS Level 1 | AU data centre |
| Telephony / SMS | SignalWire | HIPAA eligible, SOC 2 | US (AU PSTN) |
| Resend | SOC 2 Type II | US (GDPR compliant) | |
| Voice Synthesis | ElevenLabs | GDPR compliant | EU/US |
We're on a deliberate path to SOC 2 Type II. Here's where we are and where we're going.
Enterprise clients can request our security documentation, DPA, and sub-processor list. We're an open book.