Security Policy
September 5, 2026
1. Our commitment
Orathos is an enterprise backup and disaster recovery platform operated by EVYNUM. We apply defense-in-depth security across infrastructure, application, operations, and customer-facing controls because our customers rely on the Service to protect business-critical data.
This Security Policy describes measures we use to safeguard the Service. It does not modify the disclaimers, liability limits, or customer responsibilities in the Terms of Service.
2. Data protection and encryption
Backup data is protected using industry-standard safeguards, including AES-256 encryption for data at rest and TLS for data in transit, subject to your configuration and deployment model.
Where BYOS is enabled, encryption and key management may involve credentials and key material under your control. You are responsible for securing storage accounts, access keys, and rotation policies for BYOS destinations.
3. Access controls and tenant isolation
The Service uses logical multi-tenant isolation to separate customer workspaces, backup metadata, and administrative boundaries. Role-based access control (RBAC) limits actions within a workspace according to assigned permissions.
Users can enable two-factor authentication (2FA) to reduce account takeover risk. API tokens and agent credentials should be scoped, rotated, and stored securely.
4. Monitoring, audit logs, and incident response
We maintain audit logs for sensitive administrative actions within the Service where enabled by product capabilities. Logs help customers review access and configuration changes affecting backup operations.
We monitor infrastructure and application telemetry for reliability and security events. Our incident response procedures include investigation, containment, remediation, and customer notification where required by law or contract.
5. Vulnerability management and responsible disclosure
We assess and remediate vulnerabilities affecting the Service using risk-based prioritization. Security updates may be deployed without prior notice where necessary to protect customers.
If you believe you have discovered a security vulnerability in Orathos, report it responsibly to support@orathos.com with sufficient detail to reproduce the issue. Do not publicly disclose vulnerabilities before we have had a reasonable opportunity to investigate and remediate.
Unless expressly authorized in writing by EVYNUM, you must not perform penetration testing, automated scanning, or disruptive security testing against production systems.
6. Customer responsibilities
Security is a shared responsibility. You must protect account credentials, enforce MFA where appropriate, restrict workspace membership, secure systems running backup agents, and regularly test restores.
You are responsible for compliance obligations related to data you back up, including lawful basis, notice, retention, and cross-border transfer requirements applicable to your organization.