Insights / Category
Data, Privacy & Security
Data boundaries, tenant isolation, access and security across a group of companies.
Data, Privacy & Security ·
Shared infrastructure, separate data
How a group of companies can share technology without building a cross-product user graph. The data boundaries Oryvelon sets for each company, why marketing consent is not product consent, and what every product plans for from day one.
Data, Privacy & Security ·
Data retention and deletion: schedules, flows, backups and logs
Keeping data costs money, adds risk and rarely helps. How each Oryvelon company sets its own data retention schedule, builds deletion flows that reach every copy, handles backups and logs honestly, and treats AI prompts, caches and indexes as data that must be deleted too.
Data, Privacy & Security ·
Tenant isolation explained: separate databases, schemas and row-level security
Tenant isolation decides whether one customer's data can ever appear in another customer's screen, report or AI answer. We compare separate databases, separate schemas and row-level isolation, and explain why Oryvelon isolates at two levels: between companies and between each company's customers.
Data, Privacy & Security ·
Child data minimisation in edtech: what to collect, what to refuse and who decides
Edtech products that serve children should collect the least data that lets learning work, and treat the school as the party that decides. How we approach child data minimisation at EduRelia: schools as controllers, consent that makes sense to families, and a written list of things we will not collect.
Data, Privacy & Security ·
Marketing consent vs product consent: why we keep them separate in every company
Agreeing to use a product is not agreeing to be marketed to. How Oryvelon separates product consent from marketing consent, keeps consent records inside each company, and refuses to build cross-brand marketing lists — plus the data model, wording and checks that make the separation hold.
Data, Privacy & Security ·
Least-privilege access for small teams: roles, contractors, 2FA and access reviews
Small teams tend to give everyone admin because it is faster. A practical least-privilege access model for startups and small companies: role-based access, time-limited contractor accounts, mandatory 2FA, quarterly access reviews and a same-day offboarding routine — and how we run it across Oryvelon's companies.
Data, Privacy & Security ·
Secrets management basics: API keys, rotation and keeping credentials out of code
API keys and credentials cause some of the most avoidable security incidents in small companies. The secrets management basics we apply across Oryvelon: keys only on the server, separate keys per company and environment, scoped permissions, scheduled rotation, and a firm rule that secrets never go into repositories, tickets or chat.
Data, Privacy & Security ·
Environments and test data: local, preview, staging and production without real personal data
Most small companies test with copies of production data because it is easy. How we set up local, preview, staging and production environments across Oryvelon's companies, build synthetic test data that behaves like the real thing, and keep production personal data out of every environment except production.
Data, Privacy & Security ·
Domain, DNS and email security for a multi-brand group
How we protect the domains, DNS and email of every Oryvelon company: registration and ownership, registrar locks and auto-renew, one DNS standard, and SPF, DKIM and DMARC on every sending domain. A practical baseline any group running several brands can copy.
Work with Oryvelon