1. Introduction and Scope
Orygn LLC ("Company", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy outlines our practices regarding the collection, use, and disclosure of information through the Diligence Desk application (the "Platform"). By using the Platform, you consent to the data practices described in this policy. This policy adheres to the principles of data minimization and purpose limitation.
2. Zero-Knowledge Architecture
The Platform utilizes a "Local-First" engineering paradigm to ensure that your diligence activities remain private.
A. Volatile Memory Processing
Search queries (e.g., entity names, CAGE codes) are processed in volatile memory. Depending on the data source, requests are sent directly from your browser to the federal API or proxied through a stateless serverless function solely to manage API authentication headers. In no event are search terms committed to a persistent database log.
B. Local Persistence
User-generated data, such as "Audit History," "Saved Reports," or "Watchlists," is stored exclusively within your browser's LocalStorage, SessionStorage, or IndexedDB. This data remains physically compliant with your device's security model and is not synchronized to Orygn LLC's cloud infrastructure.
3. Data Collection Practices
While we avoid collecting Personal Identifiable Information (PII), the following technical data is processed to maintain service integrity:
- Network Telemetry: We process IP addresses, User-Agent strings, and TLS handshake metadata to prevent Denial of Service (DoS) attacks and ensure compatibility with modern encryption standards.
- Bot Mitigation: We utilize Cloudflare Turnstile to distinguish human users from automated scripts. This interaction is governed by Cloudflare's separate privacy policy and may involve the analysis of hardware interactions.
- Correspondence: If you elect to contact us via email at daniel@orygn.tech, we retain the correspondence record, including your email address and message content, for legal and support purposes.
4. Use of Information
We use the limited information we collect for the following specific purposes:
- To provide, operate, and maintain the Platform.
- To allow you to access third-party federal datasets securely.
- To detect, prevent, and address technical issues and security breaches.
- To comply with legal obligations, including responding to lawful subpoenas or court orders.
5. Third-Party Data Disclaimers
The Platform acts as an interface for public data provided by the United States Government. We do not own, create, or control this data. Primary inputs include the System for Award Management (SAM.gov), the Department of Labor (DOL) Enforcement Database, and USASpending.gov. Errors in source data must be corrected with the respective federal agency.
6. Children's Privacy
Our Services are not directed to persons under 18. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided us with personal information, we will take steps to delete such information. Compliance with the Children's Online Privacy Protection Act (COPPA) is a priority for Orygn LLC.
7. International Data Transfers
The Platform is hosted in the United States and is intended for use by United States entities pursuant to U.S. federal contracting regulations. If you access the Platform from outside the United States, you acknowledge that your data will be transferred to and processed in the United States, where data protection laws may differ from those of your jurisdiction.
8. Data Security
We implement commercially reasonable security measures to protect your information, including HTTPS enforcement (TLS 1.2/1.3), Content Security Policies (CSP), and HTTP Strict Transport Security (HSTS). However, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security.
9. Changes to This Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and upgrading the "Effective Date" at the top of this policy. You are advised to review this Privacy Policy periodically for any changes.
10. Cookies and Tracking Technologies
We use cookies and similar tracking technologies (like web beacons and tags) to track the activity on our Platform and store certain information. Tracking technologies are used to maintain session integrity (e.g., specific to Cloudflare Turnstile security tokens) and to improve and analyze our Service. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Platform (specifically those requiring security verification).