Skip to content
Trust Through Transparency

Orchestry Security and Compliance

Security, privacy, and compliance are built into Orchestry from day one. We’re SOC 2 Type II certified and committed to protecting your Microsoft 365 environment at every layer.

soc-2-logo-2-min

SOC 2 Type II Certified

Orchestry is proud to be SOC 2 Type II certified, a designation that reflects our ongoing commitment to the Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. Our SOC 2 Type II report is the result of an independent third-party audit that validates not only the design of our internal controls but also their operational effectiveness over time.
Footer - Azure

Secure by Design

Orchestry is designed to enhance Microsoft 365 management by emphasizing security, efficiency, and user-centric design. Key architectural aspects include:

  • Hosted on Microsoft Azure: Orchestry leverages Azure's robust security infrastructure, benefiting from advanced features like encryption, secure access controls, and threat detection to ensure data protection at every level.   
  • No Content Storage: The platform operates without storing any Microsoft 365 content, ensuring that data remains within the customer's environment.   
  • Tenant Isolation: Each customer's environment is logically separated, promoting data security and integrity.   
  • Integration with Microsoft 365: Orchestry integrates seamlessly with Microsoft Teams, SharePoint, and other Microsoft 365 services, enhancing collaboration and productivity.   
  • User-Centric Design: The platform's design philosophy focuses on intuitive user experiences, balancing functionality with accessibility.
Orchestry - Blog - Unlock Copilot Revenue 001-1

Data Encryption & Secure Infrastructure

We use industry-standard encryption to keep your data safe at all times.
 
Data in transit is protected using TLS 1.2+, and data at rest is secured with AES-256 encryption, the same level of protection trusted by major financial institutions. These controls help ensure your information remains private, secure, and tamper-proof as it moves through and resides within our systems.
Drata 001

Real-Time Drata Security Monitoring

Orchestry uses Drata for continuous, real-time security monitoring. With automated threat detection and instant alerts, we respond swiftly to risks, keeping your environment secure around the clock.
 
We follow DevSecOps principles, integrating security into every stage of the development lifecycle. This includes:
 
  • Regular vulnerability scans and patching 
  • Penetration testing 
  • Annual third-party audits 
  • Rigorous change management protocols
Independent Third-Party Security Testing

To maintain the highest security standards, Beacon undergoes regular independent third-party security testing. These rigorous tests validate our security measures and ensure we meet industry best practices for protecting your data.

Self-Host Your Own Data

For partners who prefer to manage their own data, Orchestry offers self-hosting options. This flexibility allows you to host your data within your own environment, providing an additional layer of control and security.

Build Confidently on Orchestry

Security isn’t a feature, it’s a foundation. We’re proud to partner with organizations around the world that trust Orchestry to simplify Microsoft 365 governance without compromising security.

Frequently Asked Questions

  • 1. Does Orchestry store my data?

    No. Orchestry does not store your Microsoft 365 content. All documents, sites, teams, and associated metadata remain securely within your Microsoft 365 environment.

  • 2. What happens if I uninstall Orchestry?

    Uninstalling Orchestry has no impact on your existing content. Your SharePoint sites, Teams, and configurations remain intact and under your control.

  • 3. How safe is my data?

    Very safe. Orchestry is SOC 2 Type II certified, uses enterprise-grade encryption, and does not require Global Admin permissions. You can also choose to host data in your own Azure environment for maximum control.

  • 4. Will my data be transferred across Azure boundaries?

    No, data stays in the same geo where the tenant is hosted.

No. Orchestry does not store your Microsoft 365 content. All documents, sites, teams, and associated metadata remain securely within your Microsoft 365 environment.

Uninstalling Orchestry has no impact on your existing content. Your SharePoint sites, Teams, and configurations remain intact and under your control.

Very safe. Orchestry is SOC 2 Type II certified, uses enterprise-grade encryption, and does not require Global Admin permissions. You can also choose to host data in your own Azure environment for maximum control.

No, data stays in the same geo where the tenant is hosted.