legal
Security
last updated: August 12, 2026
Security is structural at Oryn: we minimize what we store, delegate the sensitive parts to specialized providers, and verify everything server-side.
1. Encryption
All traffic between your browser and Oryn is encrypted with TLS (HTTPS). Data stored by our providers is encrypted at rest.
2. Authentication
Sign-in is handled by Clerk, a dedicated authentication provider. Oryn never stores your password. Session tokens are short-lived, cryptographically signed, and verified server-side on every API request — access control is enforced by the backend, not just the interface.
3. Payments
Payments are processed by Stripe, a PCI-DSS Level 1 certified provider. Your card details are entered on Stripe's secure checkout and never pass through or get stored on Oryn's servers. Subscription events from Stripe are accepted only with a verified cryptographic signature.
4. Data minimization
We collect the minimum data needed to run the service — an email address, a subscription status and basic technical logs. The less we hold, the less can be exposed. See our Privacy Policy for details.
5. Infrastructure
The website is hosted on Vercel's global infrastructure with automatic HTTPS and isolated build environments. Dependencies are kept up to date and audited for known vulnerabilities.
6. Reporting a vulnerability
If you believe you have found a security vulnerability in Oryn, please report it to contact@oryn.news with enough detail to reproduce it. We ask that you give us reasonable time to fix the issue before public disclosure, and that you avoid accessing other users' data. We do not pursue good-faith researchers who follow these guidelines.
Questions about this page? Contact us at contact@oryn.news.