Skip to content

Try Resonance 2 early.

Tell us a little about yourself and what you’re building.

A brief description of your use case.

We’ll use these details to review your application and contact you about access. Privacy policy

Explore oruk

Security and trust

Understand how your audio is processed, what Oruk keeps, and which deployment terms are available before you integrate.

Updated September 26, 2026

Request a security review →

API content

Oruk’s own inference services discard request audio after processing. Resonance 2 WebSocket sessions buffer audio in memory until reset or session closure; an in-flight analysis keeps its committed audio until it finishes. Raw audio is not saved in the durable Resonance 2 replay record. Optional speaker diarization uses task processors that temporarily retain uploaded audio for up to 48 hours.

Model training

Oruk does not use customer audio or outputs to train, fine-tune, or evaluate models without your explicit written agreement.

Account security

Optional authenticator-app two-factor authentication protects password and connected-account sign-ins. Setup requires a verified code, recovery codes are single-use, and sensitive changes require a recent sign-in. Manage it in Account → Security.

Credentials

Passwords and API key secrets are stored only in non-recoverable form. Complete API keys are shown once.

Transport

Public website, account, billing, and inference traffic use encrypted HTTPS connections.

Stored records

Account, billing, audit, and usage metadata are encrypted at rest with restricted access.

Payments

Card details are collected in a secure hosted checkout and are not stored by Oruk. Subscription activation and usage allowances are verified before access is granted.

What is kept, and for how long

Request identifiers, model, task, audio duration, usage, and timestamps are retained for billing, security, and support. These records do not contain your audio or transcript. Contact our team for the retention and deletion requirements applicable to your deployment.

DataRetention
Audio sent to the APIOruk’s own inference services discard request audio after processing. Resonance 2 WebSocket sessions buffer audio in memory until reset or session closure; an in-flight analysis keeps its committed audio until it finishes. Raw audio is not saved in the durable Resonance 2 replay record. Optional speaker diarization uses task processors that temporarily retain uploaded audio for up to 48 hours.
Demo and playground file uploadsDemo and playground files selected for batch testing are staged in a private temporary cache before you click Run. Upload handles expire after 10 minutes. Replacing a file or closing the demo requests deletion sooner. Staged files are not used for training.
Model outputs — transcripts, emotion and speaking-style labelsCompleted Resonance 2 result payloads, including expression scores, are stored for durable settlement and authorized same-ID replay. Replay is available for 24 hours; this is not a physical-deletion deadline. These replay records contain no raw audio or transcript and are separate from request metadata. The speaker diarization processor retains its job output for up to 24 hours.
Request metadata — request and key IDs, model, task, audio duration, cost, timestampsRetained for billing, abuse prevention, and audit.
Account records — name, email, password hashRetained while the account is open; deleted on request.
Subscription and billing recordsRetained as required for accounting and tax.
Consented measurement identifiersEligible for measurement for up to 90 days; cleared on consent withdrawal or by scheduled cleanup after expiry.

How requests and usage limits work

Your request is authenticated before speech processing begins. API access, the selected plan, and available usage are checked together. Your result is returned through an encrypted connection. In addition to billing and operational metadata, Oruk stores completed Resonance 2 result payloads for durable settlement and authorized same-ID replay; these replay records contain no raw audio or transcript.

01 / Authenticate

Keys are checked for expiration, revocation, and active organization access.

02 / Check allowance

Your trial or subscription allowance and spending limit are checked before processing.

03 / Record usage

Successful requests record measured audio usage. Failed processing releases the reserved allowance.

Processing and deployment

Enabling optional speaker diarization sends audio to a task processor. File requests use its Media API: uploaded audio is deleted within 48 hours and speaker-label job output within 24 hours under the provider’s published retention policy. Live sessions stream audio to its WebSocket service. These processing paths are not a promise of zero retention across all providers.

See pyannoteAI's data retention policy. A SOC 2 report does not establish HIPAA compliance or replace a Business Associate Agreement.

Spectra-2 processes audio in North America, Europe, or Asia, routing each request by proximity, service health, and available capacity. Other standard speech inference remains in the United States. Optional task processing may occur outside the United States. If your application requires a specific processing region, retention term, or deployment boundary, confirm the complete configuration with Oruk before sending audio.

Payment and marketing systems do not receive API audio or model outputs. Feature-specific processing and deletion terms are available during a security review.

Availability and contractual terms

These are the current boundaries of the standard offering. A discussion of enterprise requirements does not establish a contract or a custom deployment; any additional commitments must be agreed in writing.

Certification

No SOC 2, no ISO 27001, and no third-party security audit.

Healthcare

No HIPAA Business Associate Agreement. Protected health information should not be sent to the public API. Raise it with us first if PHI is in scope.

Contracts

No published DPA. Data-processing terms are handled during enterprise review.

Metadata expiry

Billing and audit metadata have no universal automatic expiry. Access, correction, and deletion requests are handled at access@oruk.ai. Consented measurement identifiers expire separately.

Service levels

Standard self-serve subscriptions do not include a contractual uptime SLA. The status page reports current checks and published incidents.

Model accuracy, demographic fairness, and the limits of emotion and speaking-style labels are covered separately under responsible use, with benchmark methodology and caveats on the methodology page.

Incident handling

Report a suspected security issue to access@oruk.ai. Reports are triaged by impact, contained, investigated, and communicated to affected customers when required.

Contracts and review

Security questionnaires, data-processing terms, and deployment requirements are handled during an enterprise review. Public commitments remain in the Privacy Policy and Terms.

View service status