Skip to content

Security & privacy

Where your data lives, who can reach it, and what leaves.

The app answers this from your account, not from a policy page. Support has no screen that opens your books: a missing screen, not a promise.

01 · Privacy & dataWhere it is stored+Encrypted on top of that+Who can reach it+What leaves, and to whom+

Where it is stored, and who can reach it

Built from your account, so everything on it is true for this space right now.

Settings · Privacy & data

Where the app and the database run, what is encrypted on the disk, and what leaves the space.

Where it is stored

The application
London, United Kingdom, on managed infrastructure behind a firewall.
The database itself
Amsterdam, in the EU, managed the same way.
From the open internet
The database accepts none; only the application reaches it.

Encrypted on top of that

With our key, before anything touches the disk, so a stolen database dump is only ciphertext.

Uploaded receipts and documents
Encrypted with our key on the way to the disk.
Bank, exchange, messenger credentials
Encrypted with our key, and never shown back to anyone, not even you.
What a statement scan read
Encrypted with our key, in the same way as the file it was read out of.
Card identity data
Kept only until the issuer accepts it, then deleted.
Wallet keystores
Ciphertext only, encrypted in your browser; we never hold the seed.

Who can reach it

People in this space
Exactly what their role allows, and nothing at all from your other spaces.
Agents you connected
Never more than you could do yourself, recomputed on every call.
Orla staff
The shape of the account: plan, connections, whether a sync is failing. Not the contents, and every action logged for you to read.

What leaves, and to whom

Only the companies that receive something because of what this space switched on. Nothing is sold, and analytics can be switched off.

Anthropic, for Copilot and scans
What a question needs, plus the contents of the file being scanned.
The open banking provider
Behind your bank links, and your banking password never reaches Orla.
The exchanges you connected
Read-only, by the key you made there.
Public blockchain nodes
Asked about the addresses you watch.
AMLBot, screening a destination
It receives the address, not you.
02 · Document encryptionHow the vault works+Your own storage+

Files we could not open if we wanted to

Not for support, not for a court order, not by mistake. Documents are encrypted in your browser before they reach us; amounts and names stay in the ledger we compute on.

How the vault works

What it covers
Receipts, statements and documents, all encrypted in this browser before they reach us at all.
What it does not cover
Amounts, names and the rest of the ledger, which we hold and compute on.
The vault phrase
Twelve characters or more, and not your sign-in password; we never see it.
The recovery code
Shown once and never again: we keep no copy of it, so print it.
The key while you work
It lives in this tab and dies with it; a remembered browser asks for a passkey instead of the phrase you typed.
If both are lost
Nobody opens the files again, so they can at least be erased. Switching the add-on off later never locks you out of them.

Your own storage

Google Drive
One folder of Orla's own, and nothing else in your Drive is visible to it.
An S3 bucket you own
AWS, Cloudflare R2 or MinIO, where the files stay ciphertext too, so your provider cannot read them any more than we can.
New uploads
Go straight to your bucket once it is connected, and the plan's storage limit stops counting those spaces: the bytes are yours, not ours.
The files already here
Moving them over is paused for now; the block says so and counts what has moved. They stay in Orla's storage, encrypted as always, and open as usual until the move resumes.
If the add-on lapses
Only new uploads go back to Orla. What is in your bucket stays there and opens as before, and the keys are kept until every file is back.
03 · Getting inWays in+

Every way in, and every way back out

A password reset ends every session before it, and a revoked session stops on its next request.

Security · Devices

Every device with when it signed in and when it expires, one press to sign the others out, and the security log underneath.

Ways in

Passkey
Face or finger on this device, and a fresh challenge the server checks rather than a remembered session.
Password
Twelve characters at least, and changing it signs out every other device, even one you have lost.
Google, or an Ethereum wallet
If you would rather not have a password at all.
Authenticator code
Attempts are capped, then the account locks.
Recovery codes
Single use, printed once; the last method you have left cannot be removed.
A step up for dangerous things
A passkey or a code at the moment, for settings that would let money out.
04 · Before money movesA crypto send, step by step+What asks for what+

Something you have, and something you know

A crypto send needs the passkey and the wallet password, not either one. A payment over the threshold waits for a second person, whatever you confirmed.

Payments · the queue for signature

A batch above the threshold waits for the rule's signatures, and whoever prepared it never signs it.

A crypto send, step by step

Step one, the passkey
A fresh challenge the server checks, with face or finger; until it answers, the server does not release the encrypted key at all.
Step two, the wallet password
It decrypts the key, and it is not your sign-in password; typed by you.
Where the key is meanwhile
Encrypted in your browser, decrypted only for the signature, never by us.
A copied session elsewhere
Has neither the passkey nor the password, so it signs nothing at all.

What asks for what

Signing in
A passkey, or a password and a code.
A crypto send
The passkey and the wallet password.
Opening the vault
The vault phrase, or a passkey on a browser that you chose to remember.
Releasing a payment
Your own signature, and a second person's once the threshold is passed.
Changing security settings
Asked again at the moment: an allowlist, an approval rule or a payout list.
05 · IP allowlistHow a rule behaves+

A space that only opens from your own addresses

Per space, so signing in is never gated by it, and denials go to the same log.

Security · Network

A rule is an address or a range, with a label and a date after which it stops working.

How a rule behaves

A range or one address
A whole range in the notation you already use, or a single address, with an expiry date if you want one.
Where a key is used
The build machine that calls the API gets a rule of its own, not only the desk where a person sits.
Outside every rule
Refused before it reaches this space's data, and logged as a denial.
Locked yourself out
A recovery link by email opens one door for one network for thirty minutes, pinned to the address that used it; it never switches the allowlist off.
An address a request cannot prove
Counts as a denial, so stripping a header is not a way around the check.
Two spaces, one person
One person can be in a restricted space and an open one at once, and the two never affect each other.
06 · Team & accessWhat each role starts with+The nineteen switches+Hidden sections+

A role is where a person starts, and the switches decide the rest.

Every action that changes the books asks for its own switch, not for the role: a switch turned off is refused whatever the role says. A guest in a group space sees the group, and nothing of yours.

Team & access

Each person with their role, what they can see and sign; an accountant reads and exports, and never signs.

What each role starts with

Owner
One per space, and billing sits here. Sees everything, can do everything including deleting the space, and signs.
Admin
Sets the rules and invites people: rules, cards, connections, people. Signs.
Member
Can hold a card with a ceiling of its own, sees the accounts you tick, requests payments and spends inside a limit. Requests only, never signs; the owner can hand one the card pool.
Accountant
A seat, so nobody emails a spreadsheet: the books, the documents and the exports, to read and hand over, never to sign; the owner can add the assistant to the seat.
Agent
A machine, treated as one: the spaces you named, with masked details. It proposes and writes inside a daily cap, and it never signs.
Can only look
For the person who should see and not touch: what you allow, nothing else. The owner can hand them the ledger to write in.

The nineteen switches

Each is a lock of its own on the person's card in Team & access, on the Scale plan; the other plans use the plain roles.

Ledger
Write ledger transactions; goals, debts, recurring payments and loans ride on the same switch.
Payments
Propose payments, approve or reject payments, execute approved payments. An expense claim is proposed with the first switch and decided with the second one.
Accounts
Manage accounts & connections.
Business
Manage invoices & pay links, manage contacts, account codes & accountant exports. The tax centre's settings, the report builder's templates and the shared month card go with the last one.
Budgets, documents, cards
Manage budgets & categories, manage documents, manage the card pool.
AI & automation
Manage automation rules, and use Copilot and statement scans, which the bots in Telegram and Slack ask for as well.
Treasury and security
Swap and bridge assets, deposit to and withdraw from lending, release a wallet signing key, run paid AML screenings.
Team
Invite & manage the team, manage space settings. These two an admin can lose and nobody below an admin can be handed, because they are how a person would promote themselves.
The owner
Has no editor: every switch, always. Anyone else opens their own card and reads what they may do, so a refusal reads as a rule and not as a bug.

Hidden sections

What can be hidden
Reports, payments, the card pool, the team, documents, for a member of a business space: any section but the four that are the person's own, the home, the settings, the security section and People.
A lock, not a missing button
The section leaves the rail and the menu, its address opens a page saying it is hidden for you, every call under it is refused, its card leaves the home, and the assistant is not handed its tools.
What stays
The cash figure on the home still counts every account the person may see. The owner sees everything, Show all brings the whole cabinet back, and the member reads on their own row which sections are hidden.
In the chats
A section hidden from a person refuses the Telegram or Slack command with the same words as the page, whether the command reads it or writes it.

How we check ourselves

The parts that are not a promise.

Each of these is a check that fails a build, not an intention. Findings are fixed before the release.

Enforced by the build

Every route states who may call it
A missing rule fails CI.
Rules that ban unsafe patterns
Scanned on every commit.
A written audit after each release
With a fixed checklist, and the findings fixed first.
Webhooks with a bad signature
Refused, and never allowed to fail open.
The same payment sent twice
Refused by an idempotency key.

Watched while it runs

Failed sign-ins
Capped, then the account locks.
Providers having a bad day
An alarm on our side, and the app says so rather than inventing a number.
Errors in production
Traced, with an owner.
A stale figure
Labelled as stale, never shown as current.
Every admin action
In a log you can read on your own screen.

Boundaries

What Orla will not do, no matter who is asking.

Two of these hold even when the person asking is you: a vault we cannot open, and an agent that never signs.

Never

Move money over a bank link
We never ask for the right.
Trade on an exchange key
Refused on connect.
Hold your wallet seed
Ciphertext only, in your browser.
Open your books in support
No such screen exists.
Sell what a connection saw
Not to anyone, at any price.
Let an agent sign a payment
Or widen its own access; no setting changes that.

Yours, on request

A full export
CSV, PDF and the documents.
Deleting the account
After the export, and it is real.
Turning analytics off
And it stays off.
Taking your files elsewhere
Your own Drive or bucket.
Cutting a connection
What it imported stays yours.
A space only for your addresses
On the top plan.

Under the hood, and how to tell us

Found something? Write to us before you publish it.

The address below is the one /.well-known/security.txt names, so the address here is the address there.

Under the hood

Passwords
Hashed, never stored.
Sensitive secrets
Encrypted at rest.
Sessions
Short-lived tokens, and a refresh token in a secure, http-only cookie.
The database
Firewalled to the application.
A reused refresh token
Revokes every session at once, and the event lands in your security log.

Reporting something

Where
[email protected], or the machine-readable file at /.well-known/security.txt.
Before you publish
Tell us, and we work on it with you.
What we will not do
Threaten a researcher who acted in good faith.
What helps most
The steps, and what you expected instead.

Where this shows up

Security is a property of every part, not a page.

Accounts & connections
Read only everywhere, and a broken connection that says so instead of showing a stale number.
Payments & approvals
A threshold, two signatures, and a queue where your own request never counts as one.
Crypto & wallets
The seed encrypted on your device, screening before a send, and no send button on a watched address.
Shared, chats & agents
Guests, children, carers and machines, each narrow by default and widened only on purpose.

Questions

The answers the app gives from your own account.

Can Orla staff read my transactions?

No. Support has no screen that opens your books, and that is a missing screen rather than a policy. Every export, download and model answer is written to a data access log you can read yourself, including anything our own staff caused.

What is needed before crypto leaves?

A passkey and the wallet password, not either one on its own. Until the passkey answers, the server does not release the encrypted key at all, so the password alone is not a way in either. The passkey works with any platform authenticator, Touch ID included.

What happens to my sessions after a password reset?

Every session that existed before the reset ends. Documents can also be encrypted so that we could not open them for support, for a court order or by mistake, and switching that off later never locks you out of what is already encrypted.

See it on your own books.

Thirty minutes: we connect an account, drop a real bill in, and close a month together.