SECURITY & PRIVACY REVIEW MATERIALS

AdaptOrch Trust Center

Review the operator, data paths and published policy status before sending private inputs. These materials support due diligence; they are not a certification.

Documents
Policies and data-flow disclosures
Effective date
April 27, 2026
Maintainer
ClassicMate
Security contact
ingeng2004@gmail.com

Before you send data

AdaptOrch is the product. ClassicMate (클래식메이트) is the published service operator. Polar handles subscription payments as Merchant of Record. This page does not assert a different legal entity or certification.

Sent to the hosted service
The task payload you submit can include prompts, code/context and metadata. A local MCP client still sends the request to the hosted endpoint.
Sent to your model provider
Model-backed execution sends the configured model the inputs needed for that request. BYOK controls credentials and charges, not whether data leaves your device.
Retained records and artifacts
Run metadata, submitted content, diagnostics and generated artifacts may be retained under the published policy. Temporary runner workspaces are a different retention category.
Export and deletion
Use available report/artifact export controls and contact the published operator for account or data-deletion requests. Purging telemetry does not by itself delete all run metadata; read the retention policy for scope and exceptions.
Separate execution environment
Agree repository access, network permissions, isolation, evidence transfer and storage before a private-runner PoC. Local execution alone does not imply that no record is sent to hosted services.
Policy and certification status
Read each document’s stated draft/review status and effective date. This site does not claim ISO/ISMS certification. Policy approval and signed terms require the responsible operator; copy changes are not legal approval.

Retention & deletion · Provider data transfer · Repository-validation PoC

DOC-CLM-001

Claim Boundary

What AdaptOrch does and does not claim in CEK S3 shadow mode, including correctness_claim=false and runner-health separation.

DOC-SEC-001

Information Security Policy

How AdaptOrch protects customer data, patch evidence, API keys, and operational systems.

DOC-PRV-001

Privacy Policy

How AdaptOrch collects, uses, retains, and protects personal information for the SaaS website and application.

DOC-TOS-001

Terms of Service

Commercial and acceptable-use terms for using AdaptOrch SaaS and related APIs.

DOC-DRD-001

Data Retention and Deletion Policy

Retention windows, deletion triggers, export handling, and recovery limitations for AdaptOrch data.

DOC-KEY-001

API Key Management Policy

Lifecycle controls for creating, storing, using, rotating, revoking, and auditing AdaptOrch API keys.

DOC-BCP-001

Incident, Backup, and Recovery Policy

How AdaptOrch prepares for, detects, responds to, backs up, and recovers from service disruption or security incidents.

DOC-ACR-001

Access Control Register

A public summary of how AdaptOrch maintains role-based access records and reviews privileged access.

DOC-LLM-001

External LLM Provider Data Transfer Description

What data may be sent to external LLM providers when AdaptOrch routes review or evaluation tasks.

DOC-VDP-001

Vulnerability Disclosure Policy

Safe-harbor aligned rules for reporting suspected vulnerabilities in AdaptOrch public systems.

DOC-AUD-001

Operational Audit Log Policy

Which operational events AdaptOrch records, why they are retained, and how they support B2B trust reviews.

DOC-RFD-001

Refund & Withdrawal Policy

Statutory withdrawal rights, Polar subscription refunds, and digital-content refund limitations.

DOC-SUP-001

Support & Service Levels

Contact channels, operating hours, and response-time commitments.