SECURITY & PRIVACY REVIEW MATERIALS
AdaptOrch Trust Center
Review the operator, data paths and published policy status before sending private inputs. These materials support due diligence; they are not a certification.
Before you send data
AdaptOrch is the product. ClassicMate (클래식메이트) is the published service operator. Polar handles subscription payments as Merchant of Record. This page does not assert a different legal entity or certification.
- Sent to the hosted service
- The task payload you submit can include prompts, code/context and metadata. A local MCP client still sends the request to the hosted endpoint.
- Sent to your model provider
- Model-backed execution sends the configured model the inputs needed for that request. BYOK controls credentials and charges, not whether data leaves your device.
- Retained records and artifacts
- Run metadata, submitted content, diagnostics and generated artifacts may be retained under the published policy. Temporary runner workspaces are a different retention category.
- Export and deletion
- Use available report/artifact export controls and contact the published operator for account or data-deletion requests. Purging telemetry does not by itself delete all run metadata; read the retention policy for scope and exceptions.
- Separate execution environment
- Agree repository access, network permissions, isolation, evidence transfer and storage before a private-runner PoC. Local execution alone does not imply that no record is sent to hosted services.
- Policy and certification status
- Read each document’s stated draft/review status and effective date. This site does not claim ISO/ISMS certification. Policy approval and signed terms require the responsible operator; copy changes are not legal approval.
Retention & deletion · Provider data transfer · Repository-validation PoC
Claim Boundary
What AdaptOrch does and does not claim in CEK S3 shadow mode, including correctness_claim=false and runner-health separation.
DOC-SEC-001Information Security Policy
How AdaptOrch protects customer data, patch evidence, API keys, and operational systems.
DOC-PRV-001Privacy Policy
How AdaptOrch collects, uses, retains, and protects personal information for the SaaS website and application.
DOC-TOS-001Terms of Service
Commercial and acceptable-use terms for using AdaptOrch SaaS and related APIs.
DOC-DRD-001Data Retention and Deletion Policy
Retention windows, deletion triggers, export handling, and recovery limitations for AdaptOrch data.
DOC-KEY-001API Key Management Policy
Lifecycle controls for creating, storing, using, rotating, revoking, and auditing AdaptOrch API keys.
DOC-BCP-001Incident, Backup, and Recovery Policy
How AdaptOrch prepares for, detects, responds to, backs up, and recovers from service disruption or security incidents.
DOC-ACR-001Access Control Register
A public summary of how AdaptOrch maintains role-based access records and reviews privileged access.
DOC-LLM-001External LLM Provider Data Transfer Description
What data may be sent to external LLM providers when AdaptOrch routes review or evaluation tasks.
DOC-VDP-001Vulnerability Disclosure Policy
Safe-harbor aligned rules for reporting suspected vulnerabilities in AdaptOrch public systems.
DOC-AUD-001Operational Audit Log Policy
Which operational events AdaptOrch records, why they are retained, and how they support B2B trust reviews.
DOC-RFD-001Refund & Withdrawal Policy
Statutory withdrawal rights, Polar subscription refunds, and digital-content refund limitations.
DOC-SUP-001Support & Service Levels
Contact channels, operating hours, and response-time commitments.