Security & privacy
Plain language. No unearned badges.
This page says what we connect to, what we store, who can see it, and what we have not done yet. It does not claim certifications we do not hold.

The approval gate
The approval gate is a security control.
The most damaging thing a social tool can do to your brand is say something in public that you did not approve. The research behind this product is full of it. Oryxia's answer is architectural: every draft is held for a person; the send is theirs; the record shows who it was.
If you work in a regulated industry — clinics, finance, legal — sensitive topics can be flagged for a human instead of drafted.

What we handle, and why
Five kinds of data. Nothing else.
Instagram and TikTok account data
- Used for
- Performance analytics, published content, and inbox conversations for the accounts you connect.
- How it is handled
- Read through the platforms' official APIs with the permissions you grant. You can disconnect an account at any time and the connection is revoked.
Brand knowledge base
- Used for
- Your voice, rules, offers, people and topics — the context every draft is generated from.
- How it is handled
- Entered and edited by you. Used only to generate drafts for your workspace. Never used to train models for anyone else.
Drafts, approvals and sends
- Used for
- The audit trail: what was drafted, who approved it, what changed, when it went out.
- How it is handled
- Kept per workspace so you can answer for any public message. Visible to the seats you invite.
Media you upload
- Used for
- Raw footage and images for the video workflow.
- How it is handled
- Stored in your workspace's storage. Studio/Agency plans can connect their own cloud storage on request.
Account and billing details
- Used for
- Your login, seats and subscription.
- How it is handled
- Passwords are never stored in plain text. Card details are handled by the payment processor, not by us.
- We do not sell data. Not to advertisers, not to data brokers, not to anyone.
- Your content does not train other people's models. Your personal brain and drafts stay in your workspace.
- You can leave with your data. Disconnect accounts, export what you need, and cancel in one click.
Trust requirements we build against
Six controls, in the product today.
01
Explicit approval before live publishing
No content is published and no reply is sent without a person approving it — in the moment, or in advance for routine replies you chose to automate. There is no autopost mode for content.
02
Draft and sent are different things
A draft cannot be mistaken for a live message anywhere in the product. States are distinct, labeled and logged.
03
Audit trail for important actions
Approvals, sends, disconnects and permission changes are recorded with who and when.
04
Honest provider states
If a platform API is degraded or a provider is unavailable, the product says so rather than pretending the data is complete.
05
Tenant isolation
Strict per-workspace isolation: every record belongs to one workspace, and only the seats you invite can see it.
06
AI usage and cost visibility
You can see what the AI did and what it cost. No hidden metering.
What we have not done yet
No SOC 2. No HIPAA attestation. Not yet.
Oryxia does not currently hold SOC 2, ISO 27001 or a HIPAA attestation, and we will not put those logos on this page until we do. Oryxia handles social-media data, not medical or financial records. If you work in a regulated industry (clinics, finance) and need a signed agreement before connecting an account, ask us and we will tell you plainly what we can and cannot sign today.
Security questions, vulnerability reports, or a data request: hello@oryxia.ai. We answer within two business days.
Ask us the hard questions first.
Bring your team, your IT person, or your own list. We would rather answer before you connect an account than after.
