Deployment
Cloud, your model keys, or self-hosted.
You choose where your data goes, and we show you exactly what happens on each path.
Deployment
Cloud, your model keys, or self-hosted.
Source tables
The platform queries your data where it lives, and never copies it. One exception: the document agent, covered below.
Model training
Never on your data.
SOC 2 Type II
Observation underway
Principles
We're an early-stage company with our first customers, building out security practice as fast as we responsibly can and the principle underneath it doesn't depend on our stage. You decide where your data is stored, where Othor runs, and which model touches your numbers.
Most BI platforms give you one architecture and ask you to accept it. Pick the option that matches your risk tolerance.
We host the platform in AWS and route analysis through our model providers. Enterprise customers can request a different region where residency requires it.
Hosted, like all the SaaS tools you use.
We host the platform, you bring your own provider contract and keys. Analysis runs under the terms you already negotiated, including zero-retention tiers.
For teams with an existing AI provider or self-hosted LLM
Othor runs inside your perimeter. Paired with a model you host, no business data reaches us or any external provider. Available only for Enterprise customers.
For regulated data and strict residency requirements.
Certifications arrive on an auditor's timetable. These promises don't; they hold for Othor Cloud today. Region choice, zero-retention, and self-hosted are Enterprise options.
We don't copy your warehouse. SQL sources are queried in place — we keep the answer, not the tables behind it.
Your data is not used to train our models. Provider contracts prohibit training on submitted content. Zero-retention processing is available on Enterprise, or when you bring your own keys.
Bring your own keys, assign models per task, switch any time.
Deploy inside your own network if your data can't leave it.
No resale, no advertising use, nothing beyond required sub-processors.
Every control below carries its real status, roadmap included.
Security questionnaires usually spend three rounds establishing this. Here it is up front, including the middle column most vendors leave out.
While your account is active
Connection credentials, encrypted.
Column names, types and summary statistics
Insights, narratives and charts we generate — including the numbers inside them
Metric definitions and the SQL behind them
Workspace and dashboard configuration
Account details and usage analytics
Caches that expire on a defined TTL
Query results materialised during an analysis
Cached responses that avoid re-running identical analyses
Not stored by Othor at any point
A replica of your warehouse or production database
Payment card details
Credentials in cleartext, anywhere
The document intelligence agent is an optional feature — you decide whether to use it, per connection. Files aren't queryable the way a database is, so to analyse Drive, SFTP, or uploaded documents we have to extract their tables first. That changes three things above, and only for those connections:
Everything else holds unchanged: extracts are encrypted at rest, scoped to your workspace, never used for training, and never sold or shared. If you only connect SQL sources, none of this applies to you.
Nothing cached is used for model training. Credentials are removed when you terminate your account, and we'll put the retention behaviour of any specific connector in writing.
Othor is AI-native, so a model is genuinely in the path of your data. This covers that path and everything around it.
Source data is read to answer a question and sent to the configured model. What we keep afterwards is the generated insight, plus the metric definitions, column metadata, and short-lived caches needed to show it again. Provider contracts prohibit training on submitted content. Zero-retention processing is available on Enterprise, or with your own keys.
By default everything Othor stores lives in AWS eu-north-1 (Stockholm). Analysis may be processed by your configured model provider, which can sit outside that region unless you bring your own model or self-host. Enterprise customers can request a different region. Talk to your point of contact.
TLS 1.2 or higher on our APIs and load balancers. Data at rest in AWS uses AES-256. Connection credentials are encrypted separately and never shown back in cleartext.
Organisation admin and member roles, per-agent sharing, and Google sign-in. Each request is bound to the workspace in the session; another workspace's briefs, jobs, and sources are not readable by id. Staff access is least-privilege, logged, and revoked when someone leaves. Database policies also enforce the same workspace boundary.
Centralised logging with alerting on anomalous activity, and a documented incident response plan with named owners. If a personal-data breach affects you, we notify you without undue delay, and report to the Data Protection Board of India within the timelines the DPDP Act requires.
Peer-reviewed changes, automated dependency and vulnerability scanning, separated environments, encrypted backups with documented restore procedures, and vendor review before adoption.
The full list is published, covering infrastructure, model providers, payments, email and support tooling, with the entity, purpose, data accessed and processing region for each. Subprocessor list
A customer-facing audit log is in the product today. Workspace admins can see who connected a source, ran an analysis, or changed sharing — and export it for their own review.
SAML and OIDC single sign-on are in development. An independent penetration test is planned ahead of our SOC 2 report, with a summary available under NDA.
Rather than imply more than we've earned, here's the precise state of each item, including the ones that are months away.
Most of what Othor processes is business data. Where personal data is involved, we operate to India's DPDP Act today — breach notification to the Data Protection Board and the commitments in our Privacy Policy. Formal certification schemes don't yet exist under the Act; when they do, we'll pursue them.
Covering processing scope, sub-processors, security measures and breach notification.
Not supported today — we don't sign BAAs, so please don't connect sources containing PHI. If you have a use case that needs it, tell us; we'll consider the certification around a real need.
One email covers procurement: security@othor.ai gets you our DPA, the current sub-processor list, control documentation, and answers to your security questionnaire.
You'll get a straight answer in writing, including where the answer is "not yet". Report a suspected vulnerability to security@othor.ai and we'll acknowledge it within one business day.
This page was last reviewed in September 2026, and it changes when the product does.