Is this your company?Buyers are checking Orca here. Claim orcaforce.co free to control the listing, earn the badge buyers trust, and see who's evaluating you.
SOC2C shows the verified essentials. 6 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
Auditorraises trust
Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
Report dateraises trust
Add your most recent report period so buyers see how current your SOC 2 is.
Renewal date
Add your renewal window so buyers know your coverage is active.
Documents
List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
Hosting
Add where you host (AWS, GCP, Azure) and data residency.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Orca SOC 2 compliant?
Orca is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Orca SOC 2 Type I or Type II?
Orca is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Orca's SOC 2 for a vendor risk assessment?
Yes. Orca's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Orca penetration tested?
Orca hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Is Orca secure?
Security isn't a single yes/no, but Orca is SOC 2 Type II compliant and holds SOC 2 Type I, SOC 2 Type II. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Orca have a bug bounty or vulnerability disclosure program?
Orca hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@orcaforce.co or via a /security page (Orca lists a security contact).
Who are Orca's subprocessors?
Orca lists 10 subprocessors on its trust center, including Slack, Vanta, GitHub, Google Workspace, Confluence. Buyers use this for fourth-party risk review.
Where does Orca host or store data?
Orca's hosting and data-residency details aren't listed on SOC2C yet. The company can add where it hosts (AWS, GCP, Azure) and which data it handles.
Where is Orca's trust center or security page?
Orca's trust center is at https://trust.orcaforce.co. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
Do you use any APIs?
#### Some of Orca's applications use internal Salesforce Platform APIs such as the Metadata API. However, Orca does not store any kind of access token anywhere. Our applications also do not transmit any data outside of Salesforce via these APIs. For example, the Metadata API is used for trigger and field deployment within your Salesforce environment. It uses User Session ID for authentication, which is only accessed for the duration of an Apex transaction, and remains inaccessible for all other users besides the owner. The entire deployment process occurs within your Salesforce environment and does not require any external connections.
What kind of security audits or security programs do you have?
Orca's applications are audited by Salesforce to ensure data security via Salesforce’s security review process, which is mandatory for an ISV application to be publicly listed on the AppExchange: https://developer.salesforce.com/docs/atlas.en-us.packagingGuide.meta/packagingGuide/security\_review\_overview.htm. Adhering to Salesforce’s security requirements, Orca also has multiple internal processes to identify code vulnerabilities, including a continuous static analysis process, a strict release management process, and code reviews performed by Salesforce certified professionals. As the first security check, every proposed code change will be scanned automatically by a static code analysis engine that prevents common security vulnerabilities from being introduced into Orca's code base. The scan includes checks such as SOQL injection protection, CRUD access checks, and sharing violations. The static code analysis provides a developer with feedback that needs to be addressed prior to a code change being eligible for further code review. Furthermore, before making any changes to Orca's applications, a proposed code change is manually reviewed and tested by developers and the service owner for security issues among other factors. If the change is a more significant update to the application it may also require reviews from additional team members, which includes Salesforce certified Sharing and Visibility Architects who have extensive experience working with the Salesforce security team. When code change makes it into a new version of the application, the service owner and product owner will run the code through the Force.com Code Scanner in addition to testing in sandboxes and in Orca's own production environment. After a period of monitoring for quality issues and seeking out any issues related to the application’s security, the new version will be push-upgraded to applicable sandboxes with a much longer period of monitoring. Once Orca is confident with the new…
What are the implications of a “Salesforce native application”?
Orca is a native to Salesforce, meaning it operates entirely within your Salesforce environment except for diagnostic and usage data, feature parameters, and Salesforce’s AppExchange App Analytics feature. Salesforce native applications have the following benefits: - Enhanced security and up-time as they are contained in your Salesforce environment - Faster performance without the delay of external callouts - Real-time access to data with no delays from third-party servers - Seamless integration with other native apps on the Salesforce platform