Security & trust

Security without handing over your data.

ORINEX Workspace runs inside infrastructure you control and connects directly to Google. Your district keeps control of its Workspace data while ORINEX gives your team the tools to manage, secure, and audit it.

LOCALRuns on your infrastructure
DIRECTConnects straight to Google
SIGNEDCode-signed releases
AUDITEDAdministrative actions recorded
The architecture

We don't host your student data.

Your Workspace records stay between Google and systems you control. ORINEX doesn't operate a hosted tenant containing your directory, files, devices, or audit history.

YOUR SERVER ORINEX Workspace Windows system you control SOURCE OF TRUTH Google Workspace Your tenant, your credentials DIRECT, BOTH WAYS ORINEX Licensing and update checks only

Your infrastructure

ORINEX installs on a Windows system you control. Your Workspace data is processed there, not in an ORINEX SaaS environment.

Your credentials

ORINEX connects directly to Google using credentials issued and controlled by your district.

No remote access

ORINEX ships no remote-access agent. There is no back door for us to reach your server, and no support tooling that phones home for one. Your server stays yours.

For privacy & procurement

A simpler privacy review starts with the architecture.

When the software runs in your environment, there is a lot less vendor infrastructure holding your data to evaluate.

Hosted SaaS
  1. Assess the vendor's infrastructure and hosting
  2. Assess their staff access and internal controls
  3. Enumerate every subprocessor holding your data
  4. Review their security history and incident response
  5. Establish where student records physically live
  6. Negotiate deletion and return on termination
ORINEX Workspace
  1. Runs on infrastructure you control
  2. Uses credentials you control
  3. Google traffic stays direct
  4. No ORINEX-hosted copy of your Workspace records

Less data in our hands means less vendor-side exposure to evaluate.

ORINEX Workspace admin activity log — every administrative action with actor, target, status and time, filterable and exportable
Accountability

Every ORINEX action, on the record.

Powerful admin tools need accountability. ORINEX keeps a complete, exportable record of the administrative actions performed through it — actor, target, outcome and timestamp — filterable when you need to prove what happened. Google-side admin, sign-in and Drive activity is ingested separately, on the retention shown below.

  • Filter by actor, action type, target, or date range.
  • Export for a compliance review without opening a database.
  • Retained by design — an audit trail you can quietly trim isn't one.
  • Held on your server, in your control, like everything else.
How access is protected

Powerful access deserves strong controls.

ORINEX can perform Super Admin-level actions, so access gets its own layer of protection.

In the product today

Named accounts, least privilege

Administrators sign in as themselves, not a shared login — which is what makes the audit trail meaningful. Three roles: super admin, admin, and a genuinely read-only viewer. New accounts start as viewer.

Two-factor authentication

Standard TOTP from any authenticator app. Secrets are encrypted at rest with Windows DPAPI, backup codes are stored only as bcrypt hashes, and a super admin can require enrollment across every account.

Lockouts and session controls

Failed sign-ins trigger a lockout that lengthens with repetition. Password reuse is blocked by history, sessions log out after fifteen minutes idle, a super admin can revoke every active session, and an optional IP allowlist limits who reaches the server at all.

Encrypted secrets and protected requests

Stored credentials and application secrets are encrypted with Windows DPAPI. The interface is served over HTTPS with a certificate generated per install, and every state-changing request carries a CSRF token.

Need to verify something we haven't listed here? Ask us.

Outbound connections

Minimal data leaves your environment.

ORINEX needs a few outbound connections for licensing and updates. None of them carries your Google Workspace records.

License verification

Five fields: the license key, a machine fingerprint (a hash derived from hardware and system identifiers), the hostname, the platform, and an installation ID issued by the licensing service.

Connection metadata

What any HTTPS request carries regardless of the sender: source IP, date and time, the API path and method, the response status, the user agent, and selected headers. That is the licensing provider's log, not something ORINEX assembles.

Version and update checks

The application asks whether a newer version exists. An update downloads only when an administrator chooses to install one. Neither carries Workspace data.

Licensing notices, fallback only

Used only if the mail server you configure is unavailable. Seven fields: an opaque customer or order identifier, an installation identifier, the event type, when it was first detected, two fixed sentences ORINEX wrote describing the condition and the remedy, and an ORINEX reply address.

Google Workspace traffic goes directly between your installation and Google.

The full Data Practices statement adds the subprocessor list and the provider's own retention. Email us and we will send it.

Retention

Stored locally. Retention clearly defined.

You know what's kept, where it lives, and how long ORINEX keeps it.

Data Retention
Directory, device, group, license, calendar
Google audit events — admin and login
Google audit events — Drive activity
Bulk-operation backups and undo records
Administrator accounts and the action log
Scheduled ops, alert rules, report definitions

Application secrets are encrypted at rest using Windows DPAPI.

Updates

Updates install when you say so.

ORINEX checks whether a newer version exists and tells you. An administrator decides whether to apply it, and when. Nothing installs itself, so a release never lands in the middle of your enrollment week.

Capability

Powerful enough for real administration.

ORINEX isn't a read-only dashboard. It performs real administrative actions across your Workspace environment, including bulk account, device, and Gmail operations.

  • Search across mailboxes using Gmail queries and permanently remove matching messages when an incident requires it.
  • Suspend, deprovision, or remove accounts and devices in bulk.
  • A complete, exportable record of administrative actions performed through ORINEX, with the actor, target, and outcome.
  • Reversible bulk operations preserve an undo path; permanent actions remain fully documented in the audit history.

Need to complete a security or privacy review?

We've documented the architecture, data flows, retention, and operational practices your district may need — published here, and downloadable as a PDF for your procurement or board file.