Private environment
Run Orkestr in a dedicated managed environment or infrastructure your organization controls.
SECURITY AND CONTROL
Every project begins with explicit users, data, sources, systems, permissions, responsibilities, and operating boundaries.
HOW CONTROL WORKS
The exact tools and rules differ by deployment, but the control pattern stays clear.
A request arrives from an approved source.
The workflow identifies the request and required records.
Orkestr retrieves the operational record.
Relevant context is added to the case.
Rules, agent work, and exception handling run in one stateful process.
The workflow pauses because the case exceeds its approved boundary.
The decision and every subsequent action remain in history.
Illustrative workflow using public-safe records. The systems, permissions, and approval points are configured per deployment.
THREE TRUST PRINCIPLES
Run Orkestr in a dedicated managed environment or infrastructure your organization controls.
Only configured accounts and services are available to the task. Access can be reviewed and revoked.
Important actions can pause and wait for the right person before work continues.
CLEAR ACCESS BOUNDARIES
SECURITY FILES
These maintained public documents define reporting, authorization boundaries, public/private separation, and the latest dependency review.
SECURITY.mdSecurity policy & reportingSupported versions, responsible vulnerability reporting, and deployment responsibilities.docs/route-security-matrix.mdRoute authorization matrixPublic bootstrap, owner-scoped, and admin-only API surfaces with their enforcement points.docs/public-private-repository-boundary.mdPublic/private boundaryWhat belongs in the open-source core and what must stay in private deployment state.docs/dependency-security-review-2026-08-26.mdDependency security reviewA dated remediation record, audit result, validation gates, and rollback expectations.WHERE INFORMATION LIVES
REVIEW REQUIREMENTS