Oruk’s own inference services discard request audio after processing. Resonance 2 WebSocket sessions buffer audio in memory until reset or session closure; an in-flight analysis keeps its committed audio until it finishes. Raw audio is not saved in the durable Resonance 2 replay record. Optional speaker diarization uses task processors that temporarily retain uploaded audio for up to 48 hours.
Model training
Oruk does not use customer audio or outputs to train, fine-tune, or evaluate models without your explicit written agreement.
Account security
Optional authenticator-app two-factor authentication protects password and connected-account sign-ins. Setup requires a verified code, recovery codes are single-use, and sensitive changes require a recent sign-in. Manage it in Account → Security.
Credentials
Passwords and API key secrets are stored only in non-recoverable form. Complete API keys are shown once.
Transport
Public website, account, billing, and inference traffic use encrypted HTTPS connections.
Stored records
Account, billing, audit, and usage metadata are encrypted at rest with restricted access.
Payments
Card details are collected in a secure hosted checkout and are not stored by Oruk. Subscription activation and usage allowances are verified before access is granted.
What is kept, and for how long
Request identifiers, model, task, audio duration, usage, and timestamps are retained for billing, security, and support. These records do not contain your audio or transcript. Contact our team for the retention and deletion requirements applicable to your deployment.
Data
Retention
Audio sent to the API
Oruk’s own inference services discard request audio after processing. Resonance 2 WebSocket sessions buffer audio in memory until reset or session closure; an in-flight analysis keeps its committed audio until it finishes. Raw audio is not saved in the durable Resonance 2 replay record. Optional speaker diarization uses task processors that temporarily retain uploaded audio for up to 48 hours.
Demo and playground file uploads
Demo and playground files selected for batch testing are staged in a private temporary cache before you click Run. Upload handles expire after 10 minutes. Replacing a file or closing the demo requests deletion sooner. Staged files are not used for training.
Model outputs — transcripts, emotion and speaking-style labels
Completed Resonance 2 result payloads, including expression scores, are stored for durable settlement and authorized same-ID replay. Replay is available for 24 hours; this is not a physical-deletion deadline. These replay records contain no raw audio or transcript and are separate from request metadata. The speaker diarization processor retains its job output for up to 24 hours.
Retained for billing, abuse prevention, and audit.
Account records — name, email, password hash
Retained while the account is open; deleted on request.
Subscription and billing records
Retained as required for accounting and tax.
Consented measurement identifiers
Eligible for measurement for up to 90 days; cleared on consent withdrawal or by scheduled cleanup after expiry.
How requests and usage limits work
Your request is authenticated before speech processing begins. API access, the selected plan, and available usage are checked together. Your result is returned through an encrypted connection. In addition to billing and operational metadata, Oruk stores completed Resonance 2 result payloads for durable settlement and authorized same-ID replay; these replay records contain no raw audio or transcript.
01 / Authenticate
Keys are checked for expiration, revocation, and active organization access.
02 / Check allowance
Your trial or subscription allowance and spending limit are checked before processing.
03 / Record usage
Successful requests record measured audio usage. Failed processing releases the reserved allowance.
Processing and deployment
Enabling optional speaker diarization sends audio to a task processor. File requests use its Media API: uploaded audio is deleted within 48 hours and speaker-label job output within 24 hours under the provider’s published retention policy. Live sessions stream audio to its WebSocket service. These processing paths are not a promise of zero retention across all providers.
Spectra-2 processes audio in North America, Europe, or Asia, routing each request by proximity, service health, and available capacity. Other standard speech inference remains in the United States. Optional task processing may occur outside the United States. If your application requires a specific processing region, retention term, or deployment boundary, confirm the complete configuration with Oruk before sending audio.
Payment and marketing systems do not receive API audio or model outputs. Feature-specific processing and deletion terms are available during a security review.
Availability and contractual terms
These are the current boundaries of the standard offering. A discussion of enterprise requirements does not establish a contract or a custom deployment; any additional commitments must be agreed in writing.
Certification
No SOC 2, no ISO 27001, and no third-party security audit.
Healthcare
No HIPAA Business Associate Agreement. Protected health information should not be sent to the public API. Raise it with us first if PHI is in scope.
Contracts
No published DPA. Data-processing terms are handled during enterprise review.
Metadata expiry
Billing and audit metadata have no universal automatic expiry. Access, correction, and deletion requests are handled at access@oruk.ai. Consented measurement identifiers expire separately.
Service levels
Standard self-serve subscriptions do not include a contractual uptime SLA. The status page reports current checks and published incidents.
Model accuracy, demographic fairness, and the limits of emotion and speaking-style labels are covered separately under responsible use, with benchmark methodology and caveats on the methodology page.
Incident handling
Report a suspected security issue to access@oruk.ai. Reports are triaged by impact, contained, investigated, and communicated to affected customers when required.
Contracts and review
Security questionnaires, data-processing terms, and deployment requirements are handled during an enterprise review. Public commitments remain in the Privacy Policy and Terms.