Orithos applies defense-in-depth: encryption at rest and in transit, bcrypt hashing, Fernet encryption, RBAC, audit logging, and rate limiting.
Role-based access control (RBAC) with four roles: VIEWER (read-only), ANALYST (create scans, view results), ADMIN (manage agents, keys, users), OWNER (billing, org settings, delete). Forbidden resource access returns 404 (not 403) to avoid information leakage.
Every user action is logged with actor identity, timestamp, action type, target resource, and outcome. Logs are immutable and queryable via the API. Retention follows the organization's data retention policy.
All traffic is encrypted in transit via TLS 1.3. Data at rest is encrypted using AES-256 on the storage layer. Sensitive endpoints implement rate limiting with configurable thresholds per route. The internal API key authenticates proxy-to-backend requests without exposing user credentials.