Orato ("we," "us," "our") is committed to protecting the security and integrity of our platform, our infrastructure, and the data entrusted to us by our customers. This Security Policy outlines how we protect our systems, how data is handled across our service tiers, and the consequences of unauthorized access or misuse of our platform.
This page should be read alongside our Privacy Policy and Terms of Use/Conditions. In the event of any conflict, the Terms of Use and Privacy Policy govern.
1. Unauthorized Access and Platform Integrity
Orato's application, infrastructure, source code, models, and underlying systems are proprietary and protected under applicable intellectual property and computer misuse laws.
Any attempt to:
- Gain unauthorized access to Orato's application, servers, databases, or infrastructure
- Probe, scan, or test the vulnerability of our systems without prior written authorization
- Reverse-engineer, decompile, or extract Orato's proprietary models, prompts, or voice technology (including PersonaPlex and related fine-tuned models)
- Circumvent authentication, rate limits, or access controls
- Interfere with, disrupt, or degrade the availability of the Orato platform for other users
- Scrape, exfiltrate, or misuse customer data, call recordings, or transcripts without authorization
...constitutes a direct violation of our Privacy Policy and Terms of Use/Conditions, and may be treated as a breach of applicable law, including computer fraud, data protection, and intellectual property statutes in the relevant jurisdiction.
Such conduct may result in direct legal action from Orato Inc. and/or its affiliated entities, including but not limited to Lumatrixworks Technologies Private Limited and Sterling Events LLC, and may be reported to relevant law enforcement and regulatory authorities.
If you believe you have discovered a genuine security vulnerability in Orato's platform, we ask that you report it responsibly to security@tryorato.com (or info@tryorato.com) rather than testing it independently. We are open to working with good-faith security researchers under a responsible disclosure process (see Section 6).
2. Infrastructure and Data Security
- Encryption: Data is encrypted in transit (TLS) and at rest.
- Access controls: Role-based access controls restrict internal access to customer data on a need-to-know basis.
- Cloud infrastructure: Orato's infrastructure is hosted on secure cloud providers (e.g., Microsoft Azure, AWS) that maintain their own independent security certifications.
- Monitoring: Systems are monitored for unauthorized access attempts and anomalous activity.
- Employee access: Internal access to production systems and customer data is limited and logged.
3. Data Processing by LLM and AI Providers
Orato's platform uses large language models (LLMs) and voice AI providers to deliver core functionality (e.g., conversational intelligence, transcription, voice synthesis).
- Any data processed by third-party LLM providers is handled in accordance with the security guidelines and data processing policies published by those providers.
- We select providers that maintain enterprise-grade security and compliance practices, and we do not alter or bypass their stated data handling terms.
- Customers can request a list of current LLM/AI subprocessors by contacting info@tryorato.com.
4. Data Usage by Subscription Tier
Orato offers tiered plans with different data privacy protections:
Free Tier
Call recordings, transcripts, and associated interaction data processed on Orato's Free tier may be used to train and improve Orato's proprietary voice models (including future iterations of our voice AI technology). By using the Free tier, users acknowledge and consent to this usage.
Pro and Pro+ Tiers
Customers on Pro and Pro+ plans receive enhanced data privacy protections. Call recordings and transcripts on these tiers are not used to train Orato's proprietary models, and are handled under stricter data isolation and retention terms.
Users who require full data privacy and protection, including exclusion from model training, should upgrade to a Pro or Pro+ subscription.
For questions about which tier fits your data privacy requirements, contact info@tryorato.com.
5. Third-Party Integrations
Orato integrates with third-party platforms (e.g., CRMs, WhatsApp Business API, telephony providers). Data processed through these integrations is handled under the legal, security, and compliance protocols set out in the respective third-party vendor's own terms and conditions. Orato is not responsible for the independent data practices of third-party vendors beyond the integration scope agreed with the customer.
6. Responsible Disclosure
We welcome reports of genuine security vulnerabilities from researchers acting in good faith. To report an issue:
- Email security@tryorato.com with details sufficient to reproduce the issue
- Do not access, modify, or exfiltrate customer data while testing
- Allow us reasonable time to investigate and remediate before public disclosure
We will not pursue legal action against researchers who follow this process in good faith.
7. Contact
For questions about this Security Policy, data handling, or subscription tiers:
This Security Policy is provided for informational purposes and does not constitute a legally binding agreement independent of Orato's Terms of Use and Privacy Policy. Orato reserves the right to update this policy at any time.