← Back to OrchestriX PMO

Security

Last updated: 13 September 2026 · OrchestriX PMO Pty Ltd · Melbourne, Australia

SOC 2 compliance

We are building OrchestriX PMO towards the SOC 2 Type II Trust Services Criteria (Security, Availability, Confidentiality) and are formalising the control set ahead of a third-party audit. We have not yet completed a SOC 2 audit — if you need current compliance documentation for a vendor review, contact security@orchestrixpmo.com and we'll share exactly where we stand.

Data encryption

All data is encrypted in transit using TLS. Data at rest is encrypted at the database-platform level (AES-256 via our Postgres provider). We do not currently operate a separate customer-managed key-management layer.

Hosting and data location

OrchestriX PMO Pty Ltd is an Australian-registered company based in Melbourne, but our primary database is currently hosted in Seoul, South Korea (ap-northeast-2), not Australia. AI inference processing may also occur outside Australia. Full in-region Australian data residency is on our roadmap; this page will be updated the day it ships. Contact us if data residency is a hard requirement for your organisation and we'll confirm current status for your account.

Access control

Admin-level access is gated separately from standard user access, and admin actions are logged to an audit trail. We are moving towards more granular role-based access control beyond the current admin/non-admin model.

Authentication

Supports password authentication with bcrypt hashing and Google OAuth 2.0. Microsoft SSO and TOTP-based two-factor authentication are on our near-term roadmap but are not available yet — we will update this page the day they ship. Session tokens expire after 30 days (or 24 hours if Remember Me is not selected).

Penetration testing

We run our own internal security testing (covering the OWASP Top 10: access control, injection, authentication, and misconfiguration checks) ahead of releases. We are in the process of engaging an independent third-party penetration testing firm and will publish details here once that engagement is confirmed.

Vulnerability disclosure

To report a security vulnerability, email security@orchestrixpmo.com with subject line "Responsible Disclosure". We aim to acknowledge within 24 hours and provide a remediation timeline within 72 hours. We do not pursue legal action against good-faith researchers.

Incident response

In the event of a data breach affecting your organisation, we will notify you within 72 hours of becoming aware, in accordance with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth).

Contact

Security team: security@orchestrixpmo.com
OrchestriX PMO Pty Ltd, Melbourne VIC 3000, Australia