What Oris Work stores encrypted, how PAN is protected, and what never leaves in an export.
Each time a client’s PAN is read for a profile view, an engagement document view or an engagement-letter generation, Oris Work writes an entry to a PII access log: which field, who accessed it, in which workspace, and for what purpose. The log stores a non-reversible fingerprint of the value, never the PAN itself. Logging is best-effort and never blocks the read. There is no screen for this log in the app today.
The Clients export deliberately leaves PAN out. If you need PAN for a purpose, open the client and read it there, where access is logged.
DPDP Consent and the PII Access Log
How consent is captured for e-signing and marketing, and how sensitive-data access is recorded.
How Workspaces Are Kept Separate
A plain-language overview of how one firm’s data is kept apart from another’s.
Custom Roles
Build your own permission sets with Read, Write and Delete per module and assign them to team members.
Exporting Your Data
Download your clients, deals and activities as CSV, or a full JSON archive, from Settings.