B2B TRUST PACKAGE · PRE-ISO READY
AdaptOrch Trust Center
Trust starts with evidence boundaries. AdaptOrch separates evidence from claims, isolates runner health, and ships a security/privacy package customers can review before formal ISO/ISMS work.
Claim Boundary
What AdaptOrch does and does not claim in CEK S3 shadow mode, including correctness_claim=false and runner-health separation.
DOC-SEC-001Information Security Policy
How AdaptOrch protects customer data, patch evidence, API keys, and operational systems.
DOC-PRV-001Privacy Policy
How AdaptOrch collects, uses, retains, and protects personal information for the SaaS website and application.
DOC-TOS-001Terms of Service
Commercial and acceptable-use terms for using AdaptOrch SaaS and related APIs.
DOC-DRD-001Data Retention and Deletion Policy
Retention windows, deletion triggers, export handling, and recovery limitations for AdaptOrch data.
DOC-KEY-001API Key Management Policy
Lifecycle controls for creating, storing, using, rotating, revoking, and auditing AdaptOrch API keys.
DOC-BCP-001Incident, Backup, and Recovery Policy
How AdaptOrch prepares for, detects, responds to, backs up, and recovers from service disruption or security incidents.
DOC-ACR-001Access Control Register
A public summary of how AdaptOrch maintains role-based access records and reviews privileged access.
DOC-LLM-001External LLM Provider Data Transfer Description
What data may be sent to external LLM providers when AdaptOrch routes review or evaluation tasks.
DOC-VDP-001Vulnerability Disclosure Policy
Safe-harbor aligned rules for reporting suspected vulnerabilities in AdaptOrch public systems.
DOC-AUD-001Operational Audit Log Policy
Which operational events AdaptOrch records, why they are retained, and how they support B2B trust reviews.
DOC-RFD-001Refund & Withdrawal Policy
Statutory withdrawal rights, Polar subscription refunds, and digital-content refund limitations.
DOC-SUP-001Support & Service Levels
Contact channels, operating hours, and response-time commitments.