# Security built into every instance

Canonical URL: https://openorange.ai/security/
Updated: 2026-09-27

New OpenOrange instances run on sealed servers that install only signed releases, with staff access only while you allow it. Encrypted logs, backups, and snapshots are coming soon.

OpenOrange keeps each customer’s instance on its own server and limits who can reach it. New instances are sealed: nobody holds standing SSH access, updates arrive as signed releases, and our staff can sign in only while you open maintenance access.

## Key capabilities

- Sealed servers with no standing SSH access.
- Only signed releases install on new instances.
- Staff access only while you open it, with every opening logged.
- Encrypted conversation and request logs with the next release.

## Sealed servers

After a new instance is installed, its server is sealed: the installation keys are removed and nobody keeps standing SSH access. From then on the instance updates itself from signed releases.

## Signed releases

Every OpenOrange release is signed when it is published. A new instance checks the signature before it installs an update and refuses anything unsigned or altered.

## Access only when you allow it

When maintenance needs the server, an owner opens access for one hour from the dashboard and can end it early. Every opening, and every reveal of the server’s console password, is written to the audit log.

## Guarded actions

Privileged operations run through an executor with explicit deny rules, and each action is written to a tamper-evident log before it starts. Secret values stay in local files or secret backends.

## Encrypted logs

Coming with the next release: new instances encrypt conversation and request content at rest by default. Owners choose how long request content is kept and whether administrators can view it, and every view is audited.

## Backups and snapshots

Coming soon: opt-in daily backups and snapshots of every machine, plus nightly backups stored off the server.

## Questions

### Can OpenOrange staff sign in to my server?

Not on a new instance unless you let them. Staff can sign in only while an owner has opened one-hour maintenance access, and each opening is logged.

### Are my logs encrypted?

Encryption at rest for conversation and request content comes to new instances with the next release. Model providers you configure still see the content they process.

## Related guides

- [Privacy and audit](https://openorange.ai/privacy-and-audit/)
- [Private instances](https://openorange.ai/operator-layer/)
- [Compute](https://openorange.ai/compute/)

## Access and contact

The same infrastructure that runs agents for large organizations is opening to teams, independent builders, and individuals.

Public launch coming soon. The infrastructure behind enterprise AI, opening to everyone. Join the waitlist as an individual or a team. For enterprise access, talk to us.

Join the waitlist: https://openorange.ai/#contact
Enterprise contact: contact@openorange.ai

## Available languages

- [English](https://openorange.ai/security.md)
- [Русский](https://openorange.ai/ru/security.md)
- [Español](https://openorange.ai/es/security.md)
- [Deutsch](https://openorange.ai/de/security.md)
- [日本語](https://openorange.ai/ja/security.md)
