Security & Governance

Built for mission-critical work. Secure by design.

Architecture overview

Orvanta's architecture ensures complete separation between control plane and data plane. Every script executes in an isolated sandbox.

Client
API Gateway
Orchestrator
Worker Container
Worker Container

Encryption at rest

All databases, secret stores, and object storage volumes are encrypted at rest using AES-256 block-level encryption.

Encryption in transit

All network traffic between internal microservices and external clients is secured with TLS 1.3.

Role-Based Access Control

Fine-grained permissions model supporting exact organisational structures.

workspace.read
workspace.write
script.execute
flow.deploy
schedule.create
secret.read
secret.write
audit.view
user.invite
user.remove
group.manage
role.assign
app.publish
app.share
webhook.create
webhook.invoke
run.cancel
run.retry
log.export
settings.update
integration.connect
billing.view
sso.configure
Admin
Full workspace access
  • Manage users
  • Configure SSO
  • All permissions
Developer
Create and edit
  • Write scripts
  • Deploy flows
  • View secrets
Operator
Run only
  • Execute flows
  • View logs
  • Publish apps
Viewer
Read only
  • View runs
  • Read audits
  • View settings
Custom roles
Enterprise plan
  • Mix permissions
  • Group mapping
  • API access

Audit logging

Every state-changing action is securely logged with immutable timestamp, user, and payload data.

Timestamp
User
Action
2025-10-12T14:32:01Z
sarah@
flow.deploy
2025-10-12T14:30:15Z
system
script.exec
2025-10-12T10:15:22Z
admin@
user.invite

Container isolation

  • • Dedicated sandbox per execution
  • • Temporary filesystem cleared on exit
  • • Memory and CPU limits enforced via cgroups
  • • No shared state between parallel runs
  • • Strict 360-second execution timeout
Run 1
Run 2
Run 3

Multi-tenancy

Data is strictly isolated at the workspace level. Database rows, object storage, and secrets are tied to specific workspace IDs.

Workspace A
Workspace B
Workspace C

Zitadel SSO & SAML

Enterprise identity management integrated out of the box.

  • • SAML 2.0 and OIDC support
  • • Automatic SCIM user provisioning
  • • Just-in-Time (JIT) account creation
  • • Group claim synchronization

Compliance roadmap

SOC 2 Type II
In progress
GDPR
Compliant
ISO 27001
Roadmap

Responsible disclosure

We take security seriously. If you believe you have found a vulnerability, please contact us immediately.

security@orvanta.cloud

Ready to automate with confidence?