Your data stays yours.

Orpheus is built on a privacy-first architecture. Audio you upload is encrypted in transit and at rest, processed in isolated environments, and never used to train models.

🔒
TLS 1.3
Encryption in transit
💾
AES-256
Encryption at rest
🇺🇪
GDPR Ready
EU data handling
SOC 2 Type II
In progress
🚫
No model training
Your audio is not used to train AI models

What happens to your audio

01

Upload

Files are transmitted over TLS 1.3. They land in an isolated per-account storage bucket — no shared paths between users.

02

Process

Transcription runs in ephemeral worker environments that are discarded after each job. No persistent access to raw audio during inference.

03

Store

Transcripts and audio are encrypted at rest with AES-256. Anonymous free-tier files are deleted after 24 hours. Registered users control retention.

04

Delete

Delete any file from the console and it is removed from storage within 24 hours. Account deletion triggers a full data purge within 30 days.

Built for regulated industries

GDPR compliance

Orpheus acts as a data processor under GDPR. We provide a Data Processing Agreement (DPA) to enterprise customers, honor data subject rights (access, rectification, erasure), and maintain records of processing activities.

  • DPA available on request
  • EU data residency option for enterprise
  • Sub-processor list published
  • Right to erasure honored within 30 days

SOC 2 Type II (in progress)

We are currently undergoing our SOC 2 Type II audit. Security controls cover access management, vulnerability management, incident response, change management, and availability monitoring.

  • Audit expected Q3 2025
  • Annual penetration testing
  • Automated dependency scanning
  • Incident response SLA: 4h acknowledgement

Who can see your data

🔐
API key scoping

Keys can be scoped to read-only, write-only, or specific endpoints. Rotate or revoke any key instantly from the console.

👥
Team member permissions

Team plan includes role-based access control. Owners, editors, and viewers have distinct permission sets across jobs, keys, and billing.

📊
Audit logs

Enterprise accounts get full audit logs of who accessed what, when, and from which IP — exportable as JSON or CSV.

🔓
SSO / SAML 2.0

Enterprise customers can enforce SSO via SAML 2.0 or OIDC, disabling password-based login for all team members.

Where your data lives

Layer Provider Region Standard
CDN / Edge Cloudflare Global ISO 27001, SOC 2
Object storage Cloudflare R2 US East + EU West AES-256 at rest
Database Cloudflare D1 US East Encrypted, replicated
AI inference Cloudflare AI Global edge Ephemeral, no logging

Security questions

Is my audio used to train AI models?

No. Orpheus does not use customer audio to train, fine-tune, or evaluate any AI models. Your data is processed for transcription and then stored or deleted according to your retention settings.

Can I get a DPA (Data Processing Agreement)?

Yes. Enterprise customers can request a DPA by emailing [email protected]. We will respond within 2 business days.

Where is data stored geographically?

By default, data is stored in US East. Enterprise customers can request EU-only data residency (EU West, Frankfurt region) as an add-on.

How do I delete my data?

Individual files can be deleted from the console immediately. To delete all data, use the account deletion flow in Settings — this triggers a full purge within 30 days. API customers can also delete jobs via DELETE /v1/jobs/:id.

Do you have a bug bounty program?

We responsibly disclose all security issues. To report a vulnerability, email [email protected]. We aim to acknowledge reports within 24 hours and resolve critical issues within 7 days.

Have specific security requirements?

Talk to us about enterprise deployments, custom DPA terms, EU data residency, and SOC 2 reports.