One page. Every document.
Procurement teams: this is the URL you share internally. Every contract, policy, attestation, and machine-readable file for OOretz Factory. 12 documents in 4 categories.
Need a signed MSA, a custom DPA addendum, or a security questionnaire response? [email protected] — 2 business day turnaround.
Contract
3 documentsTerms of Service
The contract between you and OOretz when you use the factory.
Data Processing Agreement
GDPR Art. 28 processor agreement. Includes sub-processor list and Standard Contractual Clauses module reference.
Service Level Agreement (planned tiers)
99.9% / 99.95% uptime are targets on planned Team / Enterprise tiers. No contracted SLA today. Hobby and Pro are best-effort. Public component status lives at /factory/status.
Policy
2 documentsAttestation / posture
3 documentsCompliance posture
Honest table of where we stand on 9 frameworks: SOC 2, HIPAA, GDPR, CCPA, ISO 27001, EU AI Act, NIST AI RMF, PCI-DSS, FedRAMP.
Security posture
38-item engineering controls grid: encryption, access control, monitoring, key management, vendor risk, BCP.
Architecture Decision Records
Public ADRs in the Thoughtworks pattern. Shows how we made every technical trade-off and the consequences we live with.
Machine-readable
4 documentssecurity.txt
RFC 9116 — discoverable contact for security researchers + policy link.
ai.txt
AI bot opt-in/out signaling per the emerging spawning.ai spec.
llms.txt
LLM discovery file per llmstxt.org — what we are, where the canonical pages live.
Product manifest (JSON)
Structured product manifest with pricing, surfaces, compliance status, contact emails, legal links.