Back to Trust Center
Certification standard
ISO 27001
CertifiedAssurance details maintained by Orbion GmbH for customer and partner review.
View supporting evidencePublic disclosures
Security information
Policy titles shared publicly. Approved users can download the published policy PDFs.
Acceptable Use & Workstation Security
Access Control & Least Privilege
Authentication & Password
Background Screening & On/Off-boarding
Backup, Business Continuity & Disaster Recovery
Change & Release Management
Code of Business Conduct
Compliance & Regulatory Monitoring
Data Classification & Handling
Data Subject Request Workflow
Encryption & Crypto Controls
Incident Response & Breach Notification
Information Security Objectives
Information Security Policy
Information Security & Privacy Governance
Information Sharing & Transfer
Internal Audit Procedure
ISMS Change Management Procedure
ISMS Communication Plan
ISMS Monitoring & Measurement Plan
ISMS Scope & Context
Logging, Monitoring & Audit
Management Review Procedure
Nonconformity & Corrective Action Procedure
Physical Security & Environmental
Policy Management & Exception Handling
Privacy & Data-Subject Rights
Remote Access & BYOD
Secure Configuration & Hardening
Secure Software Development Lifecycle
Security & Privacy Awareness Training
Vendor & Third-Party Risk
Vulnerability & Patch Management
Third parties that process data on the organization’s behalf.
Anthropic Anthropic is a company specializing in AI safety and research, known for their language model Claude.
GDPR
GitHub, Inc. GitHub provides hosting for software development and version control using Git.
SOC 2GDPR
Google LLC A suite of cloud computing, productivity and collaboration tools, software and products developed by Google.
HIPAA
Microsoft Corporation Microsoft Azure is a cloud computing service for building, testing, deploying, and managing applications and services.
SOC 2ISO 27001ISO 42001HIPAAPCI DSSGDPRISO 9001
Modal Labs, Inc. ML/GPU compute provider for Orbion workloads (EU region; GPU compute migrating here from GCP). DPA snapshot on file (third_party/dpas/modal-dpa-2026-06-18.md); assessed in the Tool & Supplier Inventory (third_party/evidence.md, June 2026 review).
SOC 2HIPAA
Notion Labs Inc. Notion is an all-in-one workspace for notes, tasks, wikis, and collaboration.
SOC 2ISO 27001HIPAAGDPR
PostHog PostHog is an open-source product analytics platform designed for data-driven teams.
SOC 2GDPRHIPAA
Slack Technologies Slack offers a cloud-based set of proprietary team collaboration tools and services.
ISO 27001ISO 42001SOC 2HIPAAGDPR
Security safeguards published for customer and partner review.
Acceptable Use
Access Rights
Asset Inventory
Change management
Credential Management
Data Masking
Data Privacy
Disaster Recovery Planning
Encryption Key Management
Endpoint Protection
GDPR
ISO
Network Security
Policy Compliance
Resource Capacity Management
Secure Data Transfer
Secure SDLC Integration
Security Incident Management
Security Monitoring & Detection
Standard Operating Procedures (SOPs)
Utility Tool monitoring
Vulnerability Management