Octryon
Trust and security
Last updated 2 August 2026
The questions procurement asks, answered in one place rather than across three calls.
Where your data lives
On our infrastructure, in a region you choose. If your data has to stay in Canada, or in the EU, that is a setting rather than a special arrangement.
Isolation
Every customer gets a cloud project isolated to them alone. The Octryon platform is multi-tenant; your application is not. Your records are never in a shared table alongside another customer's, which is the failure mode most people are actually worried about when they ask this question.
Getting your data out
On request, at any time, without leaving first and without a retention negotiation. You get your records, your files, and the logic behind your workflows. A Vitrine site exports as plain static files you can host anywhere.
Your application runs on our runtime, so keeping it live means staying with us. We would rather state that plainly than let you discover it at renewal.
If Octryon stopped operating
The honest version of the paragraph above is that we are a small company and you would be depending on us. So here is what that dependency is bounded by.
If we ceased operating, we would give 90 days' notice before shutting anything down, keep your service running through that period, and help you get your data out during it. Ninety days because migrating a system a business actually runs on takes longer than a month, and a notice period you cannot act on is not a commitment.
What we do not currently offer is source code escrow, a third party holding the code for release if we disappear. If that is a requirement for your organisation, tell us during procurement rather than after signing, and we will talk about it.
Availability
We target 99.9% monthly uptime for production services, and have been meeting it. Support gets a same-business-day response during business hours. The specific commitment for your engagement is in the agreement you sign with us.
For context on what that has looked like in practice: a Brazilian government document-management portal has run on Octryon in production for over a year.
Who processes what
We use a small number of service providers, by category:
- Hosting
- Serves this marketing site and receives its form submissions.
- AI model processing
- Receives the text of a brief in order to generate an MVP from it, and, only when your team uses Inky, the records needed to answer a question. See Inky and your data.
- Email delivery
- Delivers messages we send you.
The named list is in the data processing agreement we sign with customers, and we will provide it on request during a security review. We will tell you before adding a provider that handles your data.
Your application data is not part of that pipeline. The brief you send us before becoming a customer and the records inside your running application are two different things, and only the first is processed to generate an MVP.
Inky and your data
Forma includes Inky, an assistant you can ask about your own data. This is the one place your application data is processed by a model rather than simply stored, so it is worth being exact about what happens.
When someone on your team asks Inky a question, the records needed to answer that question are sent to a third-party AI provider, and the answer comes back. Two things follow from that, and both are the point:
- The provider is sent one question's worth of data, not your database. Inky is not given standing access to your application and does not read it in the background.
- If your team never uses Inky, no model ever sees your application data. It is a feature you invoke, not a pipeline running underneath you.
Your data is not used to train a model, not ours and not the provider's. The provider is named in the data processing agreement we sign with you, and we will tell you before we change it.
Inky acts, it does not only answer
Inky carries out requests as well as answering them: creating and updating records, running actions, moving work through your system on behalf of the person asking. That is the point of it, and it is also the part worth understanding properly before you let it near your operation.
Three things bound what it can do:
- It acts as you, not above you. Inky uses the permissions of the person making the request. It cannot read or change anything that person could not read or change directly, so the roles and row-level rules you already set for your team apply to Inky unchanged. There is no service account with broader reach behind it.
- Approval is a setting, and it starts off. By default Inky carries out what you ask without an extra confirmation step, because stopping to approve every routine change is not an assistant. You can require approval on any action, and it is worth doing that for the destructive and bulk ones before you roll Inky out across a team.
- Every action is attributed to Inky. Its changes are recorded as its own rather than folded into the user's history, so you can see what the assistant did and undo it.
The reason those matter: an assistant that reads your records and can also act on them means the text inside your own data (a note, a supplier name, an uploaded document) is read by something capable of taking actions. Content written by someone outside your team can therefore try to influence what Inky does. This is a real property of every AI assistant that can act, not a quirk of ours, and anyone who tells you their agent is immune to it is selling something.
What contains it here is that Inky has no authority of its own. It borrows the requesting person's, every action it takes carries its name, and you decide which actions wait for a human. If you are evaluating Inky for work where that is not enough, book a call and we will go through the specifics with you.
Privacy by default
This website sets no cookies and runs no analytics, tracking pixels, advertising networks, or session recording. There is no consent banner because there is nothing to consent to. Full detail is in the privacy policy.
Who can see your data
Access is limited to the people who need it to operate and support your service. We do not browse customer data, and we do not use it to train anything.
What gets recorded
Forma keeps a granular audit trail: who changed what, on which record, and when. Your team's actions and Inky's are both in it, with Inky's attributed to Inky rather than to whoever asked.
This is what makes the rest of this page checkable rather than merely promised. If something in your data changed and nobody can account for it, the answer is in the record instead of in a support conversation, and if it was Inky, you can see exactly which request led to it.
If something goes wrong
If customer data is exposed, lost, or accessed by someone who should not have it, we will tell the customers affected within 72 hours of confirming it. Not after an investigation concludes. Within 72 hours, with what we know at that point, including the parts we have not worked out yet.
You will get what was affected, when it happened, what we have done, and what you may need to do at your end. Where the law requires us to notify a regulator as well, we do that too.
Reporting a problem
If you believe you have found a security issue, email security@octryon.com with the details. We will acknowledge it and tell you what we are doing about it. We will not take legal action against anyone who reports a genuine issue in good faith.
Talk to a person
If you are evaluating Octryon for an organisation, the form on our homepage is probably not for you. It asks you to describe your business in a public form, and the text goes to an AI provider to build the MVP, which is exactly what most security policies tell you not to do with internal detail.
So use this instead: book a call, or email security@octryon.com for a security review. Nothing you send either way goes near the MVP pipeline.
Questions about this page? Email hello@octryon.com and a person will answer.