Features
PricingHow it worksGigx co-pilotAppsHelp CenterBlogAboutFAQContactالعربية

Security & privacy

Layered protection for your account and your clients' data: strong authentication, optional two-factor, full control over your device sessions, and GDPR-style data tools — so your business stays secure and you stay at ease.

Authentication and access guards

JWT authentication secures every request that reaches Orcaa. Behind the scenes, four guards separate the audiences clearly: owner, admin, customer, and provider — so each user type only ever reaches what it's entitled to. Alongside email and password, Google sign-in is available through a single OAuth callback at auth.orcaa.cloud, so your team gets in fast without sacrificing the isolation between roles.

Two-factor authentication (2FA)

Every user can enable two-factor 2FA/TOTP — a time-based one-time-password code from an authenticator app — on top of their password, so a stolen password alone is no longer enough to break in. Enrolling generates recovery codes that you keep somewhere safe, to regain access if the authenticator device is lost without being locked out of your account.

Device sessions

Orcaa gives you full visibility over your sessions. Every account can review its active device sessions and use logout-all-devices to sign out everywhere at once. This is useful after losing a phone or suspecting unauthorized access — you take back control with a single click, no waiting.

Email-change verification

Changing the account email requires verification, so an address can't be swapped silently and an attacker can't quietly take over the account's recovery path. This small step closes a common gap exploited in account takeovers.

Data export, erasure, and portability

Orcaa provides GDPR-style data tools that put you in control. You can request a data export — a copy of your data for portability — or send an erasure request to delete your data. These tools support data sovereignty and portability: your data is yours to take with you or to ask to have removed, whenever you choose.

Trash, restore, and audit

Records use soft deletes, so accidental deletions can be recovered from trash rather than lost permanently — a safety net against human error. Alongside that, sensitive actions are recorded in audit logs that give an accountable trail of who did what and when, which matters especially when more than one person manages your account.

Encryption at rest

Stored data is protected with AES-256 encryption at rest, so your contents stay protected at the storage layer itself. Combined with authentication, access guards, and audit, these layers form a complete defense around your business and your clients.

A note on data use

This page describes the security mechanisms only. How data is used — including analytics — is governed by the privacy policy, which is the authoritative document for those terms.

Frequently asked questions

How does Orcaa protect signing in to my account?

JWT authentication secures every request, four guards keep each user to what it's entitled to, and you can add two-factor 2FA/TOTP on top of your password.

What happens if I lose my two-factor device?

Enrolling in two-factor generates recovery codes — keep them somewhere safe to regain access if the device is lost.

How do I log out of a device I lost?

Review your active device sessions and use logout-all-devices to sign out everywhere at once.

Can I export my data or request its deletion?

Yes. GDPR-style tools to export a copy of your data or request its erasure, with trash to recover accidental deletions.

How is my stored data protected?

With AES-256 encryption at rest, plus audit logs that record sensitive actions and give an accountable trail.

Start on a secure footing

Create your account and turn on two-factor in minutes — free for 7 days

7-day free trial · no cardYour whole business in one place, ready in minutes