Security principles

Orenda is designed around explicit access scope, verified endpoints, encrypted connectivity, and revocable access for industrial remote workflows.

Resource-level access scope

Access is granted to approved apps, devices, services, servers, or machine resources instead of giving every user broad network access.

Users, groups, and ownership

Teams can organize access by people, roles, resources, and service responsibility so reviews are easier to run and explain.

Verified endpoint identity

Device and client identity are treated as part of the trust model, helping teams avoid anonymous access paths and unmanaged endpoints.

Encrypted connectivity

Remote sessions use encrypted connectivity and are designed to avoid broad inbound plant-network exposure.

Scoped partner access

Vendor and service partner links point to one approved resource, can have an optional expiry, and remain revocable.

Revocation

Authorized teams can remove access when a support job ends, a user changes role, or an incident review requires cleanup.

Local control for operational sites

Site and operations teams keep visibility into which resources are exposed and which people or partners can reach them.

Audit-friendly structure

Clear resource names, user/group assignments, and support workflow ownership make access reviews easier than shared VPN accounts.