Keep sensitive content out of stored traces
Trace Scrubbing
Mask selected fields in stored traces using the
trace_scrubbing plugin.Trace Data Masking
Control which request and response content is written to stored traces, without changing live output.
PII Redaction
Redact personally identifiable information before requests reach the provider, then restore values in the response.
Deployment Security and Privacy
Flag deployment inputs as PII or enable output masking, so logs and traces store neither.
Data handling and access
Data Retention
How long observability data is kept per plan, and how automatic deletion works.
Data Compliance
Data handling, privacy practices and the standards Orq.ai is audited against.
Secrets
Where API Keys, provider credentials and signing secrets are stored, who can read each one, and how to rotate it.
Workspace Security
Verify domain ownership with DNS TXT records and restrict access with an IP allowlist, on the Enterprise plan.
Audit Logs
Track who changed what in a workspace, for compliance and security reviews.
Sovereign AI & ZDR
AI sovereignty across business entity, EU infrastructure, model routing and zero data retention.
EU Routing & Data Residency
Where platform data is stored by default and how EU routing and sovereign deployments change it.