# Where your data lives, who can reach it, and what leaves

URL: https://www.orla.finance/en/security
Markdown twin of that page. Append `.md` to any Orla page URL to get one.

The app answers these from your own account. Support has no screen that opens your books.

#### The short version

- Where the money is: In your bank, on your exchanges and in your own wallets, none of which Orla holds. Orla holds money in two places only, both funded by you: the prepaid card balance and an agent's wallet.
- Who signs: A person on your team. A payment over the threshold waits for a second person, and each bank you pay from has its own last press, listed rail by rail.
- What an agent does alone: Spends from its own wallet and nowhere else, with Orla signing inside the limits you set. It never signs for your accounts.
- What we do not have: No SOC 2 and no ISO 27001.
- How to leave: Export your rows, then Delete account in Settings, Privacy & data erases your personal data. An owner can delete a whole space.

#### Where it is stored, and who can reach it

Built from your account, so everything on it is true for this space right now.

##### Where it is stored

- The application: London, United Kingdom, on managed infrastructure behind a firewall.
- The database itself: Amsterdam, in the EU, managed the same way.
- From the open internet: The database accepts none; only the application reaches it.

##### Encrypted on top of that

With our key, before anything touches the disk, so a stolen database dump is only ciphertext.

- Uploaded receipts and documents: Encrypted with our key on the way to the disk.
- Bank, exchange, messenger credentials: Encrypted with our key, and never shown back to anyone, not even you.
- What a statement scan read: Encrypted with our key, in the same way as the file it was read out of.
- Card identity data: Kept only until the issuer accepts it, then deleted.
- Wallet keystores: Ciphertext only, encrypted in your browser; we never hold the seed.
- Money Orla holds: Two places only, both funded by you: the prepaid card balance and an agent's wallet, whose key Orla keeps to sign inside your limits. Nothing in your bank, exchange or own wallets.

##### Who can reach it

- People in this space: Exactly what their role allows, and nothing at all from your other spaces.
- Agents you connected: Never more than you could do yourself, recomputed on every call.
- Orla staff: The shape of the account: plan, connections, whether a sync is failing. Not the contents, and every action logged for you to read.

##### What we do not have, and how to leave

- An external certificate: No SOC 2 and no ISO 27001, and nothing here implies either. In their place: named locations, a database the internet cannot reach, encryption before disk, and a staff log you can read.
- Taking it all back: Settings, Privacy & data, Delete account erases your personal data; an owner can delete a whole space, which ends it for every member. Both ask for confirmation first, and your rows stay exportable right up to either.
- Telling us about a hole: security@orla.finance. We answer, we say what we found, and we do not argue with the finder about whether it counted.

##### What leaves, and to whom

Who receives what, because of what this space switched on. Nothing is sold.

- Anthropic, for Copilot and scans: What a question needs, plus the contents of the file being scanned.
- OpenAI, for a voice message: A voice note sent to the Telegram bot or an audio clip in Slack goes there to be turned into words, and nothing else about the space goes with it. The space's AI switch turns voice off with the rest.
- The open banking provider: Behind your bank links, and your banking password never reaches Orla.
- The exchanges you connected: Read-only, by the key you made there.
- Public blockchain nodes: Asked about the addresses you watch.
- AMLBot, screening a destination: It receives the address, not you.
- dilisense and the company registers, when you check a counterparty: The name on that contact, and a company's registration number. Only on a press.
- Telegram and Slack, once connected: What the space posts to the chats you linked, and nothing before you link one.
- Whoever runs an agent you connected: What that agent reads, inside the access you gave it.
- Email delivery and crash reporting: The two that do not depend on a setting: the mail the app sends you, and the error reports.

##### What the assistant is handed

- Keys, tokens and passwords: Cut out at the door to the model: provider and API keys, session tokens, agent wallet keys, card numbers. A statement being scanned still goes, because reading it is the job.
- Bank details of the people you pay: Masked by default: an IBAN, a wallet address, a client's email or phone reach the model as •••• 5555. Only the space owner can switch that off, and every change is a line in the activity log.
- A note you asked it to keep: Goes in as data, never as an instruction, and only from a card you pressed or from Settings. Card numbers, IBANs, keys and passwords are refused. Rolling out.
- The AI switch: The space owner turns all of it off in Privacy & data: answers, category suggestions, scans, receipt reading and voice.

#### Files we could not open if we wanted to

Not for support or a court order. Documents are encrypted in your browser; amounts and names stay in the ledger we compute on.

##### How the vault works

- What it covers: Receipts, statements and documents, all encrypted in this browser before they reach us at all.
- What it does not cover: Amounts, names and the rest of the ledger, which we hold and compute on.
- The vault phrase: Twelve characters or more, and not your sign-in password; we never see it.
- The recovery code: Shown once and never again: we keep no copy of it, so print it.
- The key while you work: It lives in this tab and dies with it; a remembered browser asks for a passkey instead of the phrase you typed.
- If both are lost: Nobody opens the files again, so they can at least be erased. Switching the add-on off later never locks you out of them.

##### Your own storage

- Google Drive: One folder of Orla's own, and nothing else in your Drive is visible to it.
- An S3 bucket you own: AWS, Cloudflare R2 or MinIO, where the files stay ciphertext too, so your provider cannot read them any more than we can.
- New uploads: Go straight to your bucket once it is connected, and the plan's storage limit stops counting those spaces: the bytes are yours, not ours.
- The files already here: Moving them over is paused for now; the block says so and counts what has moved. They stay in Orla's storage, encrypted as always, and open as usual until the move resumes.
- If the add-on lapses: Only new uploads go back to Orla. What is in your bucket stays there and opens as before, and the keys are kept until every file is back.

#### Every way in, and every way back out

A password reset or Sign out everywhere ends every session at once. A device signed out alone works up to 15 minutes on its token.

##### Ways in

- Passkey: Face or finger on this device, and a fresh challenge the server checks rather than a remembered session.
- Password: Twelve characters at least, and changing it signs out every other device, even one you have lost.
- Google, or an Ethereum wallet: If you would rather not have a password at all.
- Authenticator code: Attempts are capped, then the account locks.
- Recovery codes: Single use, printed once; the last method you have left cannot be removed.
- A step up for dangerous things: A passkey or a code at the moment, for settings that would let money out.

##### Was that you?

It was me or Not me, in the app and by email.

- A sign-in from a new device: Not me signs out the device the alert names, never the one you are answering from, and a device cannot escape it by renewing its session while you answer.
- A sign-in token used a second time: The sessions that came from it are signed out already, and the card says why.
- Five failed sign-ins inside an hour: Told once a day. Not me signs out every other device and points you to the password form.
- Somebody blocked by the IP list: Goes to the owner and the admins of that space, once a day per address, with Allow this address next to Got it.
- The email about it: Links to the card, and every answer is a line in your security log.

#### Something you know, and something you have

A crypto send needs the wallet password, plus a passkey once you switch it on. Over the threshold, a second person signs.

##### A crypto send, step by step

- The wallet password, always: It decrypts the key, and it is not your sign-in password; typed by you. Twelve characters at least, because it is the one thing in front of the encrypted key.
- The passkey, if you switched it on: Also ask for Face or Touch ID on sends: with the switch on, the server does not release the encrypted key until a fresh passkey challenge answers, so a send needs both.
- Without that switch: Before the encrypted key is released the app can ask you to confirm it is you: the account password, an authenticator code, a passkey, or the Google or wallet sign-in the account uses. One confirmation covers fifteen minutes.
- Every release is announced: When the encrypted key is handed to a signed-in session, the wallet's owner gets a notice, Wallet key was unlocked, at most one a day per wallet, so a release nobody made stands out. Releases are rate limited as well.
- Where the key is meanwhile: Encrypted in your browser, decrypted only for the signature, never by us.
- A copied session elsewhere: Has no wallet password, so it cannot decrypt the key; with the passkey switch on it is not handed the encrypted key at all.

##### Paying from your own bank: who presses last

The money never passes through Orla. Each payment passes your approval rules first; where the last press sits differs by rail.

- Revolut Business: Orla reads the account and prepares a draft. The guarantee is in the access itself: the consent is given without the right to pay. A person on your team approves the draft inside Revolut.
- Mercury: Orla reads, and requests a payment. The guarantee is in the token: it carries no Send Money permission, so nothing Orla holds can pay by itself. An admin approves or rejects the request in Mercury's own queue.
- Airwallex: Orla creates a draft batch and never submits it; Airwallex has no permission that separates the two, so the guarantee is Orla's code plus your approval workflow there.
- Slash: The honest exception: Slash has no drafts. Orla sends only when a person with the right presses Send via Slash on an approved payment; your rules in Slash are the second guard.
- Safe: Orla reads the Safe from the chain and proposes a transaction as a delegate. It never signs as an owner and never executes. The owners sign to the threshold and execute in Safe{Wallet}.

##### Mail about money

- Who it comes from: An invoice, its reminders, a receipt and a quote come from Orla, and the subject names the seller. The From line stays Orla on purpose, so a mail about money cannot pretend to come from someone else.
- Where a reply goes: To the seller: the billing email printed on the document, or else the verified address of whoever made it while they are still in the space, or else the owner's verified address.

##### What asks for what

- Signing in: A passkey, or a password and a code.
- A crypto send: The wallet password, plus the passkey where you switched it on.
- Opening the vault: The vault phrase, or a passkey on a browser that you chose to remember.
- Releasing a payment: Your own signature, and a second person's once the threshold is passed.
- Changing security settings: Asked again at the moment: an allowlist, an approval rule or a payout list.

#### A space that only opens from your own addresses

Per space, so signing in is never gated by it, and denials go to the same log.

##### How a rule behaves

- A range or one address: A whole range in the notation you already use, or a single address, with an expiry date if you want one.
- Where a key is used: The build machine that calls the API gets a rule of its own, not only the desk where a person sits.
- Outside every rule: Refused before it reaches this space's data, and logged as a denial.
- Locked yourself out: A recovery link by email opens one door for one network for thirty minutes, pinned to the address that used it; it never switches the allowlist off.
- An address a request cannot prove: Counts as a denial, so stripping a header is not a way around the check.
- Two spaces, one person: One person can be in a restricted space and an open one at once, and the two never affect each other.

#### A role is a start, the switches decide

Every action that changes the books asks for its own switch, in the app and in the bots alike; a switch turned off wins over the role.

##### What each role starts with

Three handovers below are rolling out space by space; until then only Admin and Member switches can be edited.

- Owner: One per space, and billing sits here. Sees everything, can do everything including deleting the space, and signs.
- Admin: Sets the rules and invites people: rules, cards, connections, people. Signs.
- Member: Can hold a card with a ceiling of its own, sees the accounts you tick, requests payments and spends inside a limit. Requests only, never signs; the owner can hand one the card pool.
- Accountant: A seat, so nobody emails a spreadsheet: the books, the documents and the exports, to read and hand over, never to sign; the owner can add the assistant to the seat.
- Agent: The spaces you named, with masked details, and writes inside a daily cap. It spends alone only from its own wallet, and never signs for your accounts.
- Can only look: For the person who should see and not touch: what you allow, nothing else. The owner can hand them the ledger to write in.

##### The nineteen switches

Each is a lock of its own on the person's card in Team & access, on the Scale plan; the other plans use the plain roles.

- Ledger: Write ledger transactions; goals, debts, recurring payments and loans ride on the same switch.
- Payments: Propose payments, approve or reject payments, execute approved payments. An expense claim is proposed with the first switch and decided with the second one.
- Accounts: Manage accounts & connections.
- Business: Manage invoices & pay links, manage contacts, account codes & accountant exports. The tax centre's settings, the report builder's templates and the shared month card go with the last one.
- Budgets, documents, cards: Manage budgets & categories, manage documents, manage the card pool.
- AI & automation: Manage automation rules, and use Copilot and statement scans, which the bots in Telegram and Slack ask for as well.
- Treasury and security: Swap and bridge assets, deposit to and withdraw from lending, release a wallet signing key, run paid AML screenings.
- Team: Invite & manage the team, manage space settings. These two an admin can lose and nobody below an admin can be handed, because they are how a person would promote themselves.
- The owner: Has no editor: every switch, always. Anyone else opens their own card and reads what they may do, so a refusal reads as a rule and not as a bug.

##### Hidden sections

Being switched on space by space, for business spaces.

- What can be hidden: Reports, payments, the card pool, the team, documents, for a member of a business space: any section but the four that are the person's own, the home, the settings, the security section and People.
- A lock, not a missing button: The section leaves the rail and the menu, its address opens a page saying it is hidden for you, the section's own screens refuse to load, its card leaves the home, and the built-in assistant is not handed its tools.
- What stays: Totals and search still count every account the person may see. The owner sees everything, and a member sees which sections are hidden.
- What it is not: Hiding covers the screens, the bots and the built-in assistant. A person's own AI client reads by role and ticked accounts, so keep a figure private with those.
- In the chats: A section hidden from a person refuses the Telegram or Slack command with the same words as the page, whether the command reads it or writes it.

##### Agents and outside AI clients

- A refusal leaves a line: Every refusal to an agent is written down with its reason, and stays readable after the key is revoked.
- The services an agent may pay: Host names only: IP addresses, wildcards, odd ports and logins in the address are refused. Lookalikes stay in their xn-- form. An empty list is a closed door.
- Where a host is paid: The first payment pins the host's address; a later one is refused until a person confirms it by hand. The very first goes where the host said: that is the honest edge.
- Approving an AI client over MCP: Approved only in the browser that started it; a forwarded link has no Allow. The page shows the address asking and where the answer goes.
- Reports over MCP: Details masked unless approved. An agent limited to some accounts sees only their reports, and no report lists the team or what each person spent.

#### The parts that are not a promise

Each of these is a check that fails a build, not an intention. A merge is a release here, so findings are fixed before the merge.

##### Enforced by the build

- Every route states who may call it: A missing rule fails CI.
- Rules that ban unsafe patterns: Scanned on every commit.
- A written audit before the merge: It travels in the same change as the code, with a fixed checklist, and the build fails without it. A reviewer reads the diff as an auditor would and blocks the merge on a high finding.
- Webhooks with a bad signature: Refused, and never allowed to fail open.
- The same payment sent twice: Refused by an idempotency key.

##### Watched while it runs

- Failed sign-ins: Capped, then the account locks.
- Providers having a bad day: An alarm on our side, and the app says so rather than inventing a number.
- Errors in production: Traced, with an owner.
- A stale figure: Labelled as stale, never shown as current.
- Every admin action: In a log you can read on your own screen.

#### What Orla will not do, no matter who is asking

Some of these hold even against you: a vault we cannot open, a booked amount corrected by a new record and never rewritten, an agent that never signs or widens its access.

##### Never

- Move money on its own: A bank feed only reads. A bank you pay from is connected with a key you create, and every payment on it waits for the people your rule names.
- Trade on an exchange key: Refused on connect.
- Hold your wallet seed: Ciphertext only, in your browser.
- Open your books in support: No such screen exists.
- Sell what a connection saw: Not to anyone, at any price.
- Let an agent sign for your accounts: Or widen its own access; no setting changes that. It spends on its own only from its own wallet.
- Let your own AI client move money: A personal connection has no payment tools to call.
- Rewrite an amount already booked: Not the assistant, not an agent, not you: a correction is a new record.

##### The assistant, in particular

One card, one press. Money, the team, the settings and closing a month are never batched.

- Sign a payment, or advise a signature: A brief, not a verdict.
- Decide a duplicate bill for you: It says what matched; both papers stay, and the verdict is two presses of yours.
- Block a payment that looks unusual: It explains, it never blocks.
- Cancel a subscription at the supplier, or file a return: It names the day a VAT period closes, not a filing date, and files nothing.
- Open a closed month: Never.
- Post a comment in a thread: There is no tool for it under any name, and that is a decision, not a gap.
- Change how you get in: Password, two-factor, passkeys, the email, sessions, the export, a deletion, the AI switches, allowed networks and messenger links are yours to change, on their own tabs.
- Offer a role above the asker's own: Nor the owner role, nor a child's.
- The one exception to the card: Two tax settings it changes by itself, because neither is a number on a return: which tax line a category reports on, and which month the reporting year opens on.

##### Yours, on request

- A full export: CSV, PDF and the documents.
- Deleting the account: After the export, and it is real.
- Turning analytics off: And it stays off.
- Taking your files elsewhere: Your own Drive or bucket.
- Cutting a connection: What it imported stays yours.
- A space only for your addresses: On the top plan.

#### Found something? Write to us before you publish it

The address below is the one /.well-known/security.txt names, so the address here is the address there.

##### Under the hood

- Passwords: Hashed, never stored.
- Sensitive secrets: Encrypted at rest.
- Sessions: Short-lived tokens, and a refresh token in a secure, http-only cookie.
- The database: Firewalled to the application.
- A reused refresh token: Signs out the sessions that came from it, the line of that one device and not every device, and raises a card asking whether it was you. The event lands in your security log.

##### Reporting something

- Where: security@orla.finance or /.well-known/security.txt.
- Before you publish: Tell us, and we work on it with you.
- What we will not do: Threaten a researcher who acted in good faith.
- What helps most: The steps, and what you expected instead.

#### The same rules, next to the feature they guard

- Accounts & connections: Bank feeds and exchange keys that only read, and a broken connection that says so instead of showing a stale number.
- Payments & approvals: A threshold, two signatures, and a queue where your own request never counts as one.
- Crypto & wallets: The seed encrypted on your device, screening before a send, and no send button on a watched address.
- Shared, chats & agents: Guests, children, carers and machines, each narrow by default and widened only on purpose.
