Ordinal
Privacy Policy

Trust Center

Built for procurement review

What we protect, how, and the contracts your legal team needs. Our controls are mapped to the SOC 2 Trust Services Criteria. Ordinal has not yet completed an independent SOC 2 audit — we say so plainly rather than display a badge we haven't earned.

Your data never trains models

Briefs, files and Knowledge Vault entries are used only for your orders.

Isolated per client

Row-level security means no other client can read your work.

Pay only on acceptance

Funds are held until you approve the deliverable.

Controls matrix

AreaControlSOC 2 criteria
Tenant isolationRow-level security on every client table; each client can read only its own orders, files and Knowledge Vault.CC6.1, CC6.3
EncryptionTLS in transit; data and files encrypted at rest by the hosting provider (AES-256).CC6.7
Access controlRole-based access stored server-side; privileged actions re-check the caller's role on every request.CC6.1, CC6.2
Third-party credentialsTokens you enter for live pushes (GitHub, webhooks) are used for that one request and never stored.CC6.1
Signed deliveryWebhook pushes can carry an HMAC SHA-256 signature so your systems can reject forged requests.CC6.6
Output integrityDeterministic checks on figures, citations and dates before any deliverable reaches you; failed drafts are reworked, not shipped.PI1.2, PI1.3
Change & cost controlBounded retries and per-order compute ceilings stop runaway processing.CC7.2, A1.1
Payment safetyCard data handled entirely by Stripe; funds held until you accept the work.CC9.2

Contracts for your legal team

Ready-to-review templates. Ask for a signed copy and we'll countersign.

Live integrations

Deliverables can be pushed straight into GitHub as issues, or to any HTTPS endpoint — HubSpot, Salesforce, Zapier, Make or n8n — with an optional signed payload. Access keys are used for the single push and are not kept.