Skip to content

Security & privacy

Where your data lives, who can reach it, and what leaves

The app answers these from your own account. Support has no screen that opens your books.

The short version

Where the money is →
In your bank, on your exchanges and in your own wallets, none of which Orla holds. Orla holds money in two places only, both funded by you: the prepaid card balance and an agent's wallet.
Who signs →
A person on your team. A payment over the threshold waits for a second person, and each bank you pay from has its own last press, listed rail by rail.
What an agent does alone →
Spends from its own wallet and nowhere else, with Orla signing inside the limits you set. It never signs for your accounts.
What we do not have →
No SOC 2 and no ISO 27001.
How to leave →
Export your rows, then Delete account in Settings, Privacy & data erases your personal data. An owner can delete a whole space.

Where it is stored, and who can reach it

Built from your account, so everything on it is true for this space right now.

Settings · Privacy & data

Where the app and the database run, what is encrypted on the disk, and what leaves the space.

Where it is stored

The application
London, United Kingdom, on managed infrastructure behind a firewall.
The database itself
Amsterdam, in the EU, managed the same way.
From the open internet
The database accepts none; only the application reaches it.

Encrypted on top of that

With our key, before anything touches the disk, so a stolen database dump is only ciphertext.

Uploaded receipts and documents
Encrypted with our key on the way to the disk.
Bank, exchange, messenger credentials
Encrypted with our key, and never shown back to anyone, not even you.
What a statement scan read
Encrypted with our key, in the same way as the file it was read out of.
Card identity data
Kept only until the issuer accepts it, then deleted.
Wallet keystores
Ciphertext only, encrypted in your browser; we never hold the seed.
Money Orla holds
Two places only, both funded by you: the prepaid card balance and an agent's wallet, whose key Orla keeps to sign inside your limits. Nothing in your bank, exchange or own wallets.

Who can reach it

People in this space
Exactly what their role allows, and nothing at all from your other spaces.
Agents you connected
Never more than you could do yourself, recomputed on every call.
Orla staff
The shape of the account: plan, connections, whether a sync is failing. Not the contents, and every action logged for you to read.

What we do not have, and how to leave

An external certificate
No SOC 2 and no ISO 27001, and nothing here implies either. In their place: named locations, a database the internet cannot reach, encryption before disk, and a staff log you can read.
Taking it all back
Settings, Privacy & data, Delete account erases your personal data; an owner can delete a whole space, which ends it for every member. Both ask for confirmation first, and your rows stay exportable right up to either.
Telling us about a hole
[email protected]. We answer, we say what we found, and we do not argue with the finder about whether it counted.

What leaves, and to whom

Who receives what, because of what this space switched on. Nothing is sold.

Anthropic, for Copilot and scans
What a question needs, plus the contents of the file being scanned.
OpenAI, for a voice message
A voice note sent to the Telegram bot or an audio clip in Slack goes there to be turned into words, and nothing else about the space goes with it. The space's AI switch turns voice off with the rest.
The open banking provider
Behind your bank links, and your banking password never reaches Orla.
The exchanges you connected
Read-only, by the key you made there.
Public blockchain nodes
Asked about the addresses you watch.
AMLBot, screening a destination
It receives the address, not you.
dilisense and the company registers, when you check a counterparty
The name on that contact, and a company's registration number. Only on a press.
Telegram and Slack, once connected
What the space posts to the chats you linked, and nothing before you link one.
Whoever runs an agent you connected
What that agent reads, inside the access you gave it.
Email delivery and crash reporting
The two that do not depend on a setting: the mail the app sends you, and the error reports.

What the assistant is handed

Keys, tokens and passwords
Cut out at the door to the model: provider and API keys, session tokens, agent wallet keys, card numbers. A statement being scanned still goes, because reading it is the job.
Bank details of the people you pay
Masked by default: an IBAN, a wallet address, a client's email or phone reach the model as •••• 5555. Only the space owner can switch that off, and every change is a line in the activity log.
A note you asked it to keep
Goes in as data, never as an instruction, and only from a card you pressed or from Settings. Card numbers, IBANs, keys and passwords are refused. Rolling out.
The AI switch
The space owner turns all of it off in Privacy & data: answers, category suggestions, scans, receipt reading and voice.
02 · Document encryptionHow the vault works+Your own storage+

Files we could not open if we wanted to

Not for support or a court order. Documents are encrypted in your browser; amounts and names stay in the ledger we compute on.

How the vault works

What it covers
Receipts, statements and documents, all encrypted in this browser before they reach us at all.
What it does not cover
Amounts, names and the rest of the ledger, which we hold and compute on.
The vault phrase
Twelve characters or more, and not your sign-in password; we never see it.
The recovery code
Shown once and never again: we keep no copy of it, so print it.
The key while you work
It lives in this tab and dies with it; a remembered browser asks for a passkey instead of the phrase you typed.
If both are lost
Nobody opens the files again, so they can at least be erased. Switching the add-on off later never locks you out of them.

Your own storage

Google Drive
One folder of Orla's own, and nothing else in your Drive is visible to it.
An S3 bucket you own
AWS, Cloudflare R2 or MinIO, where the files stay ciphertext too, so your provider cannot read them any more than we can.
New uploads
Go straight to your bucket once it is connected, and the plan's storage limit stops counting those spaces: the bytes are yours, not ours.
The files already here
Moving them over is paused for now; the block says so and counts what has moved. They stay in Orla's storage, encrypted as always, and open as usual until the move resumes.
If the add-on lapses
Only new uploads go back to Orla. What is in your bucket stays there and opens as before, and the keys are kept until every file is back.
03 · Getting inWays in+Was that you?+

Every way in, and every way back out

A password reset or Sign out everywhere ends every session at once. A device signed out alone works up to 15 minutes on its token.

Security · Devices

Every device with when it signed in and when it expires, one press to sign the others out, and the security log underneath.

Ways in

Passkey
Face or finger on this device, and a fresh challenge the server checks rather than a remembered session.
Password
Twelve characters at least, and changing it signs out every other device, even one you have lost.
Google, or an Ethereum wallet
If you would rather not have a password at all.
Authenticator code
Attempts are capped, then the account locks.
Recovery codes
Single use, printed once; the last method you have left cannot be removed.
A step up for dangerous things
A passkey or a code at the moment, for settings that would let money out.

Was that you?

It was me or Not me, in the app and by email.

A sign-in from a new device
Not me signs out the device the alert names, never the one you are answering from, and a device cannot escape it by renewing its session while you answer.
A sign-in token used a second time
The sessions that came from it are signed out already, and the card says why.
Five failed sign-ins inside an hour
Told once a day. Not me signs out every other device and points you to the password form.
Somebody blocked by the IP list
Goes to the owner and the admins of that space, once a day per address, with Allow this address next to Got it.
The email about it
Links to the card, and every answer is a line in your security log.

Something you know, and something you have

A crypto send needs the wallet password, plus a passkey once you switch it on. Over the threshold, a second person signs.

Payments · the queue for signature

A batch above the threshold waits for the rule's signatures, and whoever prepared it never signs it.

A crypto send, step by step

The wallet password, always
It decrypts the key, and it is not your sign-in password; typed by you. Twelve characters at least, because it is the one thing in front of the encrypted key.
The passkey, if you switched it on
Also ask for Face or Touch ID on sends: with the switch on, the server does not release the encrypted key until a fresh passkey challenge answers, so a send needs both.
Without that switch
Before the encrypted key is released the app can ask you to confirm it is you: the account password, an authenticator code, a passkey, or the Google or wallet sign-in the account uses. One confirmation covers fifteen minutes.
Every release is announced
When the encrypted key is handed to a signed-in session, the wallet's owner gets a notice, Wallet key was unlocked, at most one a day per wallet, so a release nobody made stands out. Releases are rate limited as well.
Where the key is meanwhile
Encrypted in your browser, decrypted only for the signature, never by us.
A copied session elsewhere
Has no wallet password, so it cannot decrypt the key; with the passkey switch on it is not handed the encrypted key at all.

Paying from your own bank: who presses last

The money never passes through Orla. Each payment passes your approval rules first; where the last press sits differs by rail.

Revolut Business
Orla reads the account and prepares a draft. The guarantee is in the access itself: the consent is given without the right to pay. A person on your team approves the draft inside Revolut.
Mercury
Orla reads, and requests a payment. The guarantee is in the token: it carries no Send Money permission, so nothing Orla holds can pay by itself. An admin approves or rejects the request in Mercury's own queue.
Airwallex
Orla creates a draft batch and never submits it; Airwallex has no permission that separates the two, so the guarantee is Orla's code plus your approval workflow there.
Slash
The honest exception: Slash has no drafts. Orla sends only when a person with the right presses Send via Slash on an approved payment; your rules in Slash are the second guard.
Safe
Orla reads the Safe from the chain and proposes a transaction as a delegate. It never signs as an owner and never executes. The owners sign to the threshold and execute in Safe{Wallet}.

Mail about money

Who it comes from
An invoice, its reminders, a receipt and a quote come from Orla, and the subject names the seller. The From line stays Orla on purpose, so a mail about money cannot pretend to come from someone else.
Where a reply goes
To the seller: the billing email printed on the document, or else the verified address of whoever made it while they are still in the space, or else the owner's verified address.

What asks for what

Signing in
A passkey, or a password and a code.
A crypto send
The wallet password, plus the passkey where you switched it on.
Opening the vault
The vault phrase, or a passkey on a browser that you chose to remember.
Releasing a payment
Your own signature, and a second person's once the threshold is passed.
Changing security settings
Asked again at the moment: an allowlist, an approval rule or a payout list.
05 · IP allowlistHow a rule behaves+

A space that only opens from your own addresses

Per space, so signing in is never gated by it, and denials go to the same log.

Security · Network

A rule is an address or a range, with a label and a date after which it stops working.

How a rule behaves

A range or one address
A whole range in the notation you already use, or a single address, with an expiry date if you want one.
Where a key is used
The build machine that calls the API gets a rule of its own, not only the desk where a person sits.
Outside every rule
Refused before it reaches this space's data, and logged as a denial.
Locked yourself out
A recovery link by email opens one door for one network for thirty minutes, pinned to the address that used it; it never switches the allowlist off.
An address a request cannot prove
Counts as a denial, so stripping a header is not a way around the check.
Two spaces, one person
One person can be in a restricted space and an open one at once, and the two never affect each other.

A role is a start, the switches decide

Every action that changes the books asks for its own switch, in the app and in the bots alike; a switch turned off wins over the role.

Team & access

Each person with their role, what they can see and sign; an accountant reads and exports, and never signs.

What each role starts with

Three handovers below are rolling out space by space; until then only Admin and Member switches can be edited.

Owner
One per space, and billing sits here. Sees everything, can do everything including deleting the space, and signs.
Admin
Sets the rules and invites people: rules, cards, connections, people. Signs.
Member
Can hold a card with a ceiling of its own, sees the accounts you tick, requests payments and spends inside a limit. Requests only, never signs; the owner can hand one the card pool.
Accountant
A seat, so nobody emails a spreadsheet: the books, the documents and the exports, to read and hand over, never to sign; the owner can add the assistant to the seat.
Agent
The spaces you named, with masked details, and writes inside a daily cap. It spends alone only from its own wallet, and never signs for your accounts.
Can only look
For the person who should see and not touch: what you allow, nothing else. The owner can hand them the ledger to write in.

The nineteen switches

Each is a lock of its own on the person's card in Team & access, on the Scale plan; the other plans use the plain roles.

Ledger
Write ledger transactions; goals, debts, recurring payments and loans ride on the same switch.
Payments
Propose payments, approve or reject payments, execute approved payments. An expense claim is proposed with the first switch and decided with the second one.
Accounts
Manage accounts & connections.
Business
Manage invoices & pay links, manage contacts, account codes & accountant exports. The tax centre's settings, the report builder's templates and the shared month card go with the last one.
Budgets, documents, cards
Manage budgets & categories, manage documents, manage the card pool.
AI & automation
Manage automation rules, and use Copilot and statement scans, which the bots in Telegram and Slack ask for as well.
Treasury and security
Swap and bridge assets, deposit to and withdraw from lending, release a wallet signing key, run paid AML screenings.
Team
Invite & manage the team, manage space settings. These two an admin can lose and nobody below an admin can be handed, because they are how a person would promote themselves.
The owner
Has no editor: every switch, always. Anyone else opens their own card and reads what they may do, so a refusal reads as a rule and not as a bug.

Hidden sections

Being switched on space by space, for business spaces.

What can be hidden
Reports, payments, the card pool, the team, documents, for a member of a business space: any section but the four that are the person's own, the home, the settings, the security section and People.
A lock, not a missing button
The section leaves the rail and the menu, its address opens a page saying it is hidden for you, the section's own screens refuse to load, its card leaves the home, and the built-in assistant is not handed its tools.
What stays
Totals and search still count every account the person may see. The owner sees everything, and a member sees which sections are hidden.
What it is not
Hiding covers the screens, the bots and the built-in assistant. A person's own AI client reads by role and ticked accounts, so keep a figure private with those.
In the chats
A section hidden from a person refuses the Telegram or Slack command with the same words as the page, whether the command reads it or writes it.

Agents and outside AI clients

A refusal leaves a line
Every refusal to an agent is written down with its reason, and stays readable after the key is revoked.
The services an agent may pay
Host names only: IP addresses, wildcards, odd ports and logins in the address are refused. Lookalikes stay in their xn-- form. An empty list is a closed door.
Where a host is paid
The first payment pins the host's address; a later one is refused until a person confirms it by hand. The very first goes where the host said: that is the honest edge.
Approving an AI client over MCP
Approved only in the browser that started it; a forwarded link has no Allow. The page shows the address asking and where the answer goes.
Reports over MCP
Details masked unless approved. An agent limited to some accounts sees only their reports, and no report lists the team or what each person spent.

How we check ourselves

The parts that are not a promise

Each of these is a check that fails a build, not an intention. A merge is a release here, so findings are fixed before the merge.

Enforced by the build

Every route states who may call it
A missing rule fails CI.
Rules that ban unsafe patterns
Scanned on every commit.
A written audit before the merge
It travels in the same change as the code, with a fixed checklist, and the build fails without it. A reviewer reads the diff as an auditor would and blocks the merge on a high finding.
Webhooks with a bad signature
Refused, and never allowed to fail open.
The same payment sent twice
Refused by an idempotency key.

Watched while it runs

Failed sign-ins
Capped, then the account locks.
Providers having a bad day
An alarm on our side, and the app says so rather than inventing a number.
Errors in production
Traced, with an owner.
A stale figure
Labelled as stale, never shown as current.
Every admin action
In a log you can read on your own screen.

Boundaries

What Orla will not do, no matter who is asking

Some of these hold even against you: a vault we cannot open, a booked amount corrected by a new record and never rewritten, an agent that never signs or widens its access.

Never

Move money on its own
A bank feed only reads. A bank you pay from is connected with a key you create, and every payment on it waits for the people your rule names.
Trade on an exchange key
Refused on connect.
Hold your wallet seed
Ciphertext only, in your browser.
Open your books in support
No such screen exists.
Sell what a connection saw
Not to anyone, at any price.
Let an agent sign for your accounts
Or widen its own access; no setting changes that. It spends on its own only from its own wallet.
Let your own AI client move money
A personal connection has no payment tools to call.
Rewrite an amount already booked
Not the assistant, not an agent, not you: a correction is a new record.

The assistant, in particular

One card, one press. Money, the team, the settings and closing a month are never batched.

Sign a payment, or advise a signature
A brief, not a verdict.
Decide a duplicate bill for you
It says what matched; both papers stay, and the verdict is two presses of yours.
Block a payment that looks unusual
It explains, it never blocks.
Cancel a subscription at the supplier, or file a return
It names the day a VAT period closes, not a filing date, and files nothing.
Open a closed month
Never.
Post a comment in a thread
There is no tool for it under any name, and that is a decision, not a gap.
Change how you get in
Password, two-factor, passkeys, the email, sessions, the export, a deletion, the AI switches, allowed networks and messenger links are yours to change, on their own tabs.
Offer a role above the asker's own
Nor the owner role, nor a child's.
The one exception to the card
Two tax settings it changes by itself, because neither is a number on a return: which tax line a category reports on, and which month the reporting year opens on.

Yours, on request

A full export
CSV, PDF and the documents.
Deleting the account
After the export, and it is real.
Turning analytics off
And it stays off.
Taking your files elsewhere
Your own Drive or bucket.
Cutting a connection
What it imported stays yours.
A space only for your addresses
On the top plan.

Under the hood, and how to tell us

Found something? Write to us before you publish it

The address below is the one /.well-known/security.txt names, so the address here is the address there.

Under the hood

Passwords
Hashed, never stored.
Sensitive secrets
Encrypted at rest.
Sessions
Short-lived tokens, and a refresh token in a secure, http-only cookie.
The database
Firewalled to the application.
A reused refresh token
Signs out the sessions that came from it, the line of that one device and not every device, and raises a card asking whether it was you. The event lands in your security log.

Reporting something

Where
[email protected] or /.well-known/security.txt.
Before you publish
Tell us, and we work on it with you.
What we will not do
Threaten a researcher who acted in good faith.
What helps most
The steps, and what you expected instead.

Where this shows up

The same rules, next to the feature they guard

Accounts & connections →
Bank feeds and exchange keys that only read, and a broken connection that says so instead of showing a stale number.
Payments & approvals →
A threshold, two signatures, and a queue where your own request never counts as one.
Crypto & wallets →
The seed encrypted on your device, screening before a send, and no send button on a watched address.
Shared, chats & agents →
Guests, children, carers and machines, each narrow by default and widened only on purpose.

Questions

The answers the app gives from your own account

Can Orla staff read my transactions?

No. Support has no screen that opens your books. Every export, download and model answer is written to a data access log you can read yourself, including anything our own staff caused.

What is needed before crypto leaves?

The wallet password, always: it decrypts the key in your browser and is not your sign-in password. A passkey is a switch you can add on top, and with it on the server does not release the encrypted key until the passkey answers, so a send needs both. It works with any platform authenticator, Touch ID included.

Can Orla send money from our bank account by itself?

It depends on the rail, so each is stated on its own. From Mercury Orla only requests a payment, with a token that has no Send Money permission. In Revolut Business and Airwallex it prepares a draft that a person sends inside the bank. In Slash a transfer is created when your colleague presses Send via Slash after the approvals. In a Safe it proposes, and the owners sign.

What happens to my sessions after a password reset?

Every session that existed before the reset ends. Documents can also be encrypted so that we could not open them for support, for a court order or by mistake, and switching that off later never locks you out of what is already encrypted.

See it on your own books

Thirty minutes: we connect an account, drop a real bill in, and close a month together.