Trust Center

Trust at Orai

Orai helps individuals and teams improve their communication skills through guided practice and personalized feedback. We use administrative and technical safeguards designed to protect customer information and support the confidentiality, integrity, and availability of the Orai service.

Safeguards

Security controls

Orai uses layered administrative and technical practices designed to protect customer information and support service resilience.

Encryption

Orai protects data in transit using HTTPS/TLS and uses encryption at rest provided by its production cloud infrastructure.

Access control

Access to production systems and customer information is limited to authorized personnel with a business need.

Cloud infrastructure

Orai's production environment is hosted on Google Cloud in the US-West region. Selected speech transcription may be processed using Amazon Transcribe in AWS US West (Oregon).

Security incident response

Orai maintains a documented process for identifying, investigating, containing, recovering from, and reporting security incidents.

Vulnerability management

Orai evaluates security vulnerabilities and prioritizes remediation and software updates based on risk.

Business continuity

Orai maintains backup, recovery, business-continuity, and disaster-recovery procedures designed to support service resilience.

Personnel safeguards

Personnel with access to customer information are subject to confidentiality obligations and security-awareness requirements appropriate to their responsibilities.

Service-provider management

Orai reviews providers that process customer information and maintains a public list of subprocessors.

Customer content

Enterprise customer content and AI

Orai processes enterprise customer content to provide, secure, support, and maintain the service. Enterprise audio, transcripts, presentation content, and coaching results are not used to train models made available to other customers or third-party models unless the enterprise customer expressly opts in through a separate written authorization.

Orai may use aggregated and de-identified usage information to understand and improve service performance. Orai does not attempt to re-identify that information.

Retention and deletion

Data lifecycle

Orai retains customer information only for documented service, security, legal, and operational purposes. For enterprise customers, customer content is deleted from active systems within 60 days after a verified request or service termination unless a shorter contractual period or applicable law requires otherwise. Residual copies in ordinary-course backups are designed to expire within 30 additional days.

Identifiable or account-linked product analytics are retained for up to six months. Aggregated or de-identified analytics may be retained longer.

Data location

Infrastructure and processing

Primary production environment

Google Cloud

Orai production hosting is configured in the US-West region.

Selected speech transcription

Amazon Transcribe

Where enabled, processing occurs in AWS US West (Oregon), region us-west-2.

Review all current subprocessors
Privacy

How Orai handles personal information

Orai's Privacy Policy explains the personal information Orai collects, how it is used, and the choices available to individuals.

Read the Privacy Policy
Contact

Security and privacy questions

For questions about Orai's security practices, privacy program, or subprocessors, contact [email protected].

Email Orai