Skip to content

Security and trust

The public controls below describe the production Speech API and developer portal. They deliberately avoid claiming certifications or contractual service levels oruk does not currently hold.

Last updated August 5, 2026

API content

Audio and model outputs are processed only to return the requested result and are not retained after the response.

Model training

Customer audio and outputs are not used to train, fine-tune, or evaluate models unless you explicitly agree otherwise in writing.

Credentials

Passwords and API key secrets are stored only in non-recoverable form. Complete API keys are shown once.

Transport

Public website, account, billing, and inference traffic use encrypted HTTPS connections.

Stored records

Account, billing, audit, and usage metadata use provider-managed encryption at rest and role-restricted access.

Payments

Card details are entered on Stripe-hosted pages and are not stored by oruk. Verified webhooks are required before credits are issued.

What is kept, and for how long

This is the default, and it is structural rather than only contractual: the usage ledger has no column able to hold content, and no results table exists in the schema. Audio and outputs are not stored or used to train, fine-tune, or evaluate any oruk model unless you explicitly agree otherwise in writing.

DataRetention
Audio sent to the APINot retained. Held in memory to produce the response, then discarded.
Model outputs — transcripts, emotion and speaking-style labelsNot stored. Returned to you and discarded.
Request metadata — request and key IDs, model, task, audio duration, cost, timestampsRetained for billing, abuse prevention, and audit.
Account records — name, email, password hashRetained while the account is open; deleted on request.
Billing and credit ledgerRetained as required for accounting and tax.

How a request flows

A request reaches the Cloudflare edge at speech-api.oruk.ai, which terminates TLS and forwards it to the inference origin through a private Cloudflare Tunnel. The edge injects a shared secret, strips any client-supplied copy of it, and removes forwarded-IP headers before the call; a request that arrives at the origin without that secret is refused. Only billing metadata continues to the control plane.

01 / Authenticate

Keys are validated against active organizations, expiration, revocation state, and available prepaid balance.

02 / Reserve

Each request reserves its maximum billable amount before inference, preventing concurrent overspend.

03 / Settle

Successful inference appends one idempotent usage debit. Failed requests release their reservation.

Subprocessors

No payment provider or marketing analytics service receives customer API audio.

ProviderPurposeProcessing location
CloudflareWebsite delivery, account control plane, usage records, edge security, and transactional emailGlobal routing; account records in managed infrastructure
Google CloudSpeech inferenceUnited States
StripePayment processing, saved payment methods, receipts, and invoicesStripe-managed regions
ResendFallback transactional email delivery when configuredProvider-managed regions
Google AnalyticsPublic marketing-site analytics only; excluded from authenticated account pagesProvider-managed regions

What oruk does not claim

Better learned here than in a questionnaire. These are the gaps a security or clinical-safety reviewer would otherwise have to find on their own.

Certification

No SOC 2, no ISO 27001, and no third-party security audit.

Healthcare

No HIPAA Business Associate Agreement. Protected health information should not be sent to the public API. Raise it with us first if PHI is in scope.

Account security

No multi-factor authentication on portal accounts yet. Google sign-in is available.

Contracts

No published DPA. Data-processing terms are handled during enterprise review.

Metadata expiry

Retained metadata has no automated expiry. Access, correction, and deletion requests are handled by a person at access@oruk.ai.

Service levels

No contractual SLA on pay-as-you-go. The status page reports reachability, not a commitment.

Model accuracy, demographic fairness, and the limits of emotion and speaking-style labels are covered separately under responsible use, with benchmark methodology and caveats on the methodology page.

Incident handling

Report a suspected security issue to access@oruk.ai. Reports are triaged by impact, contained, investigated, and communicated to affected customers when required.

Contracts and review

Security questionnaires, data-processing terms, and deployment requirements are handled during an enterprise review. Public commitments remain in the Privacy Policy and Terms.

View service status