Security & trust

An agent you can prove, not just trust.

Osora is built to be trusted with how your company actually works. It watches without touching, isolates every tenant, and proves every action it takes back to the human who authorized it.

SOC 2 Type I in progress (Q2 2026)GDPR alignedCCPA alignedZero-retentionTenant-scopedSigned DPA
The controls

Six guarantees. Stated plainly.

Read-only by default.

Osora watches and listens during a recording and never acts, touches, or changes anything — least privilege from the first frame.

No shadow accounts.

Osora creates no hidden bot identities and silently tracks no attendees — what is captured is what was recorded and shared.

Tenant-scoped isolation.

Your company memory stays isolated, so your recordings, graph, and skills never mix with anyone else's.

Zero-retention inference.

Model calls run zero-retention, so the inference layer keeps none of your content and trains on none of it.

Provenance by construction.

Every rule traces to a human and a moment, and every action ties to the rule that authorized it — audit builds itself.

Honest compliance.

Osora states exactly what it does and does not do, and the DPA and trust center spell out every specific.

Visual masking

Secrets never leave the browser.

API keys, tokens, and sensitive fields in a recording are detected and painted over before the frame is ever uploaded — Hotjar-style masking, applied at capture time rather than after the fact.

Osora · Visual masking
  • Sensitive DOM regions masked on the JPEG before upload
  • Masking happens client-side, at the moment of capture
  • Honest about the edges: screen video and vision frames are documented
Provenance by construction

The audit trail builds itself.

You don't reconstruct an audit after an incident. Because every rule is bound to a recording and every action to a rule, the trail already exists — queryable, complete, and tied to real human decisions.

Osora · Provenance by construction
  • Each action links to the rule and moment that permitted it
  • Contradicted rules block automated runs by default
  • Maturity gates how much authority any skill is granted
Go deeper

The trust layer, in the product.

Data processing & trust center.

Sub-processors, data handling, and the full DPA.

Trust it because you can prove it.

Provenance, isolation, and masking — built in, not bolted on.