Privacy Policy

What Orkexto collects, how it is used, who processes it, and the rights you have over it.

Effective 10 August 2026. We give at least 30 days’ notice of material changes.

This Privacy Policy explains how Orkexto, based in Houston, Texas, collects, uses, and discloses information in connection with the Orkexto platform (the "Service").

This Policy distinguishes between two categories of information: (1) information about you and your organization's personnel who use the Service ("Account Information"), where we act as the data controller, and (2) data ingested from your Connected Systems in the course of providing the Service ("Customer Data"), where we act as a data processor / service provider acting on your instructions. This distinction matters for how your rights under this Policy apply.


1. Information We Collect

1.1 Account Information (collected directly from you)

  • Name, work email address, and role, provided at signup or invitation.
  • Authentication data via Amazon Cognito (we do not store raw passwords).
  • Billing information, processed by our payment processor (Stripe) — we do not store full payment card numbers.
  • Support communications and any information you voluntarily provide to us.

1.2 Customer Data (collected from your Connected Systems, on your instruction)

  • Security findings, configuration data, asset and identity inventory, and related telemetry ingested from the third-party tools you connect (SIEM, EDR, cloud providers, vulnerability scanners, identity providers, ticketing systems), scoped to the read/write permissions you grant.

1.3 Usage Data (collected automatically)

  • Log data, device/browser information, IP address, and in-product usage analytics, collected when you use the Service.

1.4 Cookies

  • Our marketing website uses cookies for analytics and session functionality. See Section 9.

2. How We Use Information

We use Account Information and Usage Data to: provide and maintain the Service; authenticate users and enforce access controls; process billing; provide customer support; send service-related and (with consent, where required) marketing communications; monitor and improve the Service; and comply with legal obligations.

We use Customer Data solely to provide the Service to you — correlating, prioritizing, and analyzing your connected security telemetry to generate the findings, incidents, coverage analysis, and remediation recommendations described in our product documentation. We do not use Customer Data for our own independent purposes, to train models for the benefit of any party other than you, or to build customer-specific profiles for advertising.


Where the GDPR applies, our legal bases for processing Account Information are: performance of a contract (providing the Service), our legitimate interests (securing and improving the Service, subject to your rights and interests), and compliance with legal obligations. Where we process Customer Data that includes personal data on your behalf, we do so as a processor acting on your documented instructions, pursuant to a data processing agreement available on request from legal@orkexto.com.


4. AI Processing Disclosure

The Service uses artificial intelligence models — including models provided by Anthropic and OpenAI — to analyze Customer Data and generate findings, correlations, risk scores, and remediation recommendations.

4.1 Customer Data submitted to these AI providers for processing is subject to their respective enterprise/API terms, which — as of the date of this Policy — do not use API-submitted data to train their general-purpose models. We will update this section if that arrangement changes, and encourage you to review the current terms of our AI subprocessors directly.

4.2 AI-generated output is a tool to assist your security decision-making and is not independently verified fact in every instance — see the Disclaimers document for the scope of this limitation.

4.3 If your organization requires specific contractual restrictions on AI processing of your Customer Data (e.g., data residency for AI inference, or exclusion of specific data categories), contact legal@orkexto.com to discuss Enterprise-tier options.


5. Data Retention

  • Account Information: retained for as long as your account is active, and for a reasonable period afterward for legal, tax, and dispute-resolution purposes.
  • Customer Data: retained per your plan's configured retention policy and made available for export for 30 days following termination, after which it is deleted, except audit-log data retained for compliance-evidence purposes (minimum 7 years for Enterprise-tier compliance-relevant events, unless you request earlier deletion where legally permissible).
  • Usage and log data: retained for 12 months for security and product-improvement purposes.

6. Subprocessors and Third-Party Disclosure

We use the following subprocessors to provide the Service, current as of the effective date of this Policy. An up-to-date list is available on request from legal@orkexto.com.

SubprocessorPurpose
Amazon Web ServicesHosting, database, storage, identity (Cognito), and notification delivery
AnthropicAI model inference for agent-generated analysis and recommendations
OpenAIAI model inference for agent-generated analysis and recommendations
StripePayment processing
SentryApplication error tracking

We do not sell Customer Data or Account Information. We may disclose information: to comply with a legal obligation, subpoena, or court order; to protect the rights, property, or safety of Orkexto, our customers, or the public; or in connection with a merger, acquisition, or asset sale (subject to continued protection under materially equivalent terms).


7. Data Security

We maintain administrative, technical, and physical safeguards designed to protect Account Information and Customer Data, including encryption in transit and at rest, role-based access controls, tenant data isolation enforced at the database level, and least-privilege access to your Connected Systems as described in our product documentation. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.


8. International Data Transfers

We offer region-pinned data residency (United States and European Union options) for Enterprise customers, as described in our product documentation. Where data is transferred internationally, we rely on appropriate safeguards, including Standard Contractual Clauses where applicable.


9. Cookies and Tracking (Marketing Site)

Our marketing website uses cookies for essential site functionality and, where you consent (as required in your jurisdiction), for analytics. You can manage cookie preferences through our cookie banner or your browser settings. The in-product application does not use third-party advertising trackers.


10. Your Privacy Rights

Depending on your location, you may have rights to: access, correct, or delete your Account Information; object to or restrict certain processing; data portability; and withdraw consent where processing is based on consent. California residents have rights under the CCPA/CPRA, including the right to know, delete, and opt out of "sale" or "sharing" as those terms are defined by California law (we do not sell Account Information or Customer Data as defined under CCPA). To exercise these rights, contact legal@orkexto.com.

For Customer Data, requests should generally be directed to the Customer organization that controls that data, since Orkexto acts as a processor for that data; we will support Customer in responding to such requests as required by our data processing agreement.


11. Children's Privacy

The Service is intended for business use by adults and is not directed to children under 18. We do not knowingly collect personal information from children.


12. Changes to This Policy

We may update this Policy from time to time. Material changes will be notified via the Service or by email at least 30 days before taking effect.


13. Contact Us

Orkexto, Houston, Texas.

Privacy inquiries: legal@orkexto.com

General inquiries: support@orkexto.com

If you are located in the EEA/UK and believe we have not adequately addressed your concern, you have the right to lodge a complaint with your local data protection authority.

Also part of this agreement: