Security & privacy
Where your data lives, who can reach it, and what leaves.
The app answers this from your account, not from a policy page. Support has no screen that opens your books: a missing screen, not a promise.
Where it is stored, and who can reach it
Built from your account, so everything on it is true for this space right now.
Where the app and the database run, what is encrypted on the disk, and what leaves the space.
Where it is stored
- The application
- London, United Kingdom, on managed infrastructure behind a firewall.
- The database itself
- Amsterdam, in the EU, managed the same way.
- From the open internet
- The database accepts none; only the application reaches it.
Encrypted on top of that
With our key, before anything touches the disk, so a stolen database dump is only ciphertext.
- Uploaded receipts and documents
- Encrypted with our key on the way to the disk.
- Bank, exchange, messenger credentials
- Encrypted with our key, and never shown back to anyone, not even you.
- What a statement scan read
- Encrypted with our key, in the same way as the file it was read out of.
- Card identity data
- Kept only until the issuer accepts it, then deleted.
- Wallet keystores
- Ciphertext only, encrypted in your browser; we never hold the seed.
Who can reach it
- People in this space
- Exactly what their role allows, and nothing at all from your other spaces.
- Agents you connected
- Never more than you could do yourself, recomputed on every call.
- Orla staff
- The shape of the account: plan, connections, whether a sync is failing. Not the contents, and every action logged for you to read.
What leaves, and to whom
Only the companies that receive something because of what this space switched on. Nothing is sold, and analytics can be switched off.
- Anthropic, for Copilot and scans
- What a question needs, plus the contents of the file being scanned.
- The open banking provider
- Behind your bank links, and your banking password never reaches Orla.
- The exchanges you connected
- Read-only, by the key you made there.
- Public blockchain nodes
- Asked about the addresses you watch.
- AMLBot, screening a destination
- It receives the address, not you.
Files we could not open if we wanted to
Not for support, not for a court order, not by mistake. Documents are encrypted in your browser before they reach us; amounts and names stay in the ledger we compute on.
How the vault works
- What it covers
- Receipts, statements and documents, all encrypted in this browser before they reach us at all.
- What it does not cover
- Amounts, names and the rest of the ledger, which we hold and compute on.
- The vault phrase
- Twelve characters or more, and not your sign-in password; we never see it.
- The recovery code
- Shown once and never again: we keep no copy of it, so print it.
- The key while you work
- It lives in this tab and dies with it; a remembered browser asks for a passkey instead of the phrase you typed.
- If both are lost
- Nobody opens the files again, so they can at least be erased. Switching the add-on off later never locks you out of them.
Your own storage
- Google Drive
- One folder of Orla's own, and nothing else in your Drive is visible to it.
- An S3 bucket you own
- AWS, Cloudflare R2 or MinIO, where the files stay ciphertext too, so your provider cannot read them any more than we can.
- New uploads
- Go straight to your bucket once it is connected, and the plan's storage limit stops counting those spaces: the bytes are yours, not ours.
- The files already here
- Moving them over is paused for now; the block says so and counts what has moved. They stay in Orla's storage, encrypted as always, and open as usual until the move resumes.
- If the add-on lapses
- Only new uploads go back to Orla. What is in your bucket stays there and opens as before, and the keys are kept until every file is back.
Every way in, and every way back out
A password reset ends every session before it, and a revoked session stops on its next request.
Every device with when it signed in and when it expires, one press to sign the others out, and the security log underneath.
Ways in
- Passkey
- Face or finger on this device, and a fresh challenge the server checks rather than a remembered session.
- Password
- Twelve characters at least, and changing it signs out every other device, even one you have lost.
- Google, or an Ethereum wallet
- If you would rather not have a password at all.
- Authenticator code
- Attempts are capped, then the account locks.
- Recovery codes
- Single use, printed once; the last method you have left cannot be removed.
- A step up for dangerous things
- A passkey or a code at the moment, for settings that would let money out.
Something you have, and something you know
A crypto send needs the passkey and the wallet password, not either one. A payment over the threshold waits for a second person, whatever you confirmed.
A batch above the threshold waits for the rule's signatures, and whoever prepared it never signs it.
A crypto send, step by step
- Step one, the passkey
- A fresh challenge the server checks, with face or finger; until it answers, the server does not release the encrypted key at all.
- Step two, the wallet password
- It decrypts the key, and it is not your sign-in password; typed by you.
- Where the key is meanwhile
- Encrypted in your browser, decrypted only for the signature, never by us.
- A copied session elsewhere
- Has neither the passkey nor the password, so it signs nothing at all.
What asks for what
- Signing in
- A passkey, or a password and a code.
- A crypto send
- The passkey and the wallet password.
- Opening the vault
- The vault phrase, or a passkey on a browser that you chose to remember.
- Releasing a payment
- Your own signature, and a second person's once the threshold is passed.
- Changing security settings
- Asked again at the moment: an allowlist, an approval rule or a payout list.
A space that only opens from your own addresses
Per space, so signing in is never gated by it, and denials go to the same log.
A rule is an address or a range, with a label and a date after which it stops working.
How a rule behaves
- A range or one address
- A whole range in the notation you already use, or a single address, with an expiry date if you want one.
- Where a key is used
- The build machine that calls the API gets a rule of its own, not only the desk where a person sits.
- Outside every rule
- Refused before it reaches this space's data, and logged as a denial.
- Locked yourself out
- A recovery link by email opens one door for one network for thirty minutes, pinned to the address that used it; it never switches the allowlist off.
- An address a request cannot prove
- Counts as a denial, so stripping a header is not a way around the check.
- Two spaces, one person
- One person can be in a restricted space and an open one at once, and the two never affect each other.
A role is where a person starts, and the switches decide the rest.
Every action that changes the books asks for its own switch, not for the role: a switch turned off is refused whatever the role says. A guest in a group space sees the group, and nothing of yours.
Each person with their role, what they can see and sign; an accountant reads and exports, and never signs.
What each role starts with
- Owner
- One per space, and billing sits here. Sees everything, can do everything including deleting the space, and signs.
- Admin
- Sets the rules and invites people: rules, cards, connections, people. Signs.
- Member
- Can hold a card with a ceiling of its own, sees the accounts you tick, requests payments and spends inside a limit. Requests only, never signs; the owner can hand one the card pool.
- Accountant
- A seat, so nobody emails a spreadsheet: the books, the documents and the exports, to read and hand over, never to sign; the owner can add the assistant to the seat.
- Agent
- A machine, treated as one: the spaces you named, with masked details. It proposes and writes inside a daily cap, and it never signs.
- Can only look
- For the person who should see and not touch: what you allow, nothing else. The owner can hand them the ledger to write in.
The nineteen switches
Each is a lock of its own on the person's card in Team & access, on the Scale plan; the other plans use the plain roles.
- Ledger
- Write ledger transactions; goals, debts, recurring payments and loans ride on the same switch.
- Payments
- Propose payments, approve or reject payments, execute approved payments. An expense claim is proposed with the first switch and decided with the second one.
- Accounts
- Manage accounts & connections.
- Business
- Manage invoices & pay links, manage contacts, account codes & accountant exports. The tax centre's settings, the report builder's templates and the shared month card go with the last one.
- Budgets, documents, cards
- Manage budgets & categories, manage documents, manage the card pool.
- AI & automation
- Manage automation rules, and use Copilot and statement scans, which the bots in Telegram and Slack ask for as well.
- Treasury and security
- Swap and bridge assets, deposit to and withdraw from lending, release a wallet signing key, run paid AML screenings.
- Team
- Invite & manage the team, manage space settings. These two an admin can lose and nobody below an admin can be handed, because they are how a person would promote themselves.
- The owner
- Has no editor: every switch, always. Anyone else opens their own card and reads what they may do, so a refusal reads as a rule and not as a bug.
Hidden sections
- What can be hidden
- Reports, payments, the card pool, the team, documents, for a member of a business space: any section but the four that are the person's own, the home, the settings, the security section and People.
- A lock, not a missing button
- The section leaves the rail and the menu, its address opens a page saying it is hidden for you, every call under it is refused, its card leaves the home, and the assistant is not handed its tools.
- What stays
- The cash figure on the home still counts every account the person may see. The owner sees everything, Show all brings the whole cabinet back, and the member reads on their own row which sections are hidden.
- In the chats
- A section hidden from a person refuses the Telegram or Slack command with the same words as the page, whether the command reads it or writes it.
How we check ourselves
The parts that are not a promise.
Each of these is a check that fails a build, not an intention. Findings are fixed before the release.
Enforced by the build
- Every route states who may call it
- A missing rule fails CI.
- Rules that ban unsafe patterns
- Scanned on every commit.
- A written audit after each release
- With a fixed checklist, and the findings fixed first.
- Webhooks with a bad signature
- Refused, and never allowed to fail open.
- The same payment sent twice
- Refused by an idempotency key.
Watched while it runs
- Failed sign-ins
- Capped, then the account locks.
- Providers having a bad day
- An alarm on our side, and the app says so rather than inventing a number.
- Errors in production
- Traced, with an owner.
- A stale figure
- Labelled as stale, never shown as current.
- Every admin action
- In a log you can read on your own screen.
Boundaries
What Orla will not do, no matter who is asking.
Two of these hold even when the person asking is you: a vault we cannot open, and an agent that never signs.
Never
- Move money over a bank link
- We never ask for the right.
- Trade on an exchange key
- Refused on connect.
- Hold your wallet seed
- Ciphertext only, in your browser.
- Open your books in support
- No such screen exists.
- Sell what a connection saw
- Not to anyone, at any price.
- Let an agent sign a payment
- Or widen its own access; no setting changes that.
Yours, on request
- A full export
- CSV, PDF and the documents.
- Deleting the account
- After the export, and it is real.
- Turning analytics off
- And it stays off.
- Taking your files elsewhere
- Your own Drive or bucket.
- Cutting a connection
- What it imported stays yours.
- A space only for your addresses
- On the top plan.
Under the hood, and how to tell us
Found something? Write to us before you publish it.
The address below is the one /.well-known/security.txt names, so the address here is the address there.
Under the hood
- Passwords
- Hashed, never stored.
- Sensitive secrets
- Encrypted at rest.
- Sessions
- Short-lived tokens, and a refresh token in a secure, http-only cookie.
- The database
- Firewalled to the application.
- A reused refresh token
- Revokes every session at once, and the event lands in your security log.
Reporting something
- Where
- [email protected], or the machine-readable file at /.well-known/security.txt.
- Before you publish
- Tell us, and we work on it with you.
- What we will not do
- Threaten a researcher who acted in good faith.
- What helps most
- The steps, and what you expected instead.
Where this shows up
Security is a property of every part, not a page.
- Accounts & connections →
- Read only everywhere, and a broken connection that says so instead of showing a stale number.
- Payments & approvals →
- A threshold, two signatures, and a queue where your own request never counts as one.
- Crypto & wallets →
- The seed encrypted on your device, screening before a send, and no send button on a watched address.
- Shared, chats & agents →
- Guests, children, carers and machines, each narrow by default and widened only on purpose.
Questions
The answers the app gives from your own account.
Can Orla staff read my transactions?
No. Support has no screen that opens your books, and that is a missing screen rather than a policy. Every export, download and model answer is written to a data access log you can read yourself, including anything our own staff caused.
What is needed before crypto leaves?
A passkey and the wallet password, not either one on its own. Until the passkey answers, the server does not release the encrypted key at all, so the password alone is not a way in either. The passkey works with any platform authenticator, Touch ID included.
What happens to my sessions after a password reset?
Every session that existed before the reset ends. Documents can also be encrypted so that we could not open them for support, for a court order or by mistake, and switching that off later never locks you out of what is already encrypted.
See it on your own books.
Thirty minutes: we connect an account, drop a real bill in, and close a month together.