generated: '2026-07-21' method: searched source: https://useorigin.com/resources/blog/technical-overview notes: Origin is a consumer fintech (Blend Financial Inc. DBA Origin Financial) with no public API surface; conformance entries here reflect the company's published compliance posture rather than API protocol conformance. standards: - id: soc2-type2 conforms: true evidence: '"SOC2 Type II certified" — https://useorigin.com/resources/blog/technical-overview; Vanta-hosted trust center at https://trust.useorigin.com/' - id: gdpr conforms: true evidence: '"GDPR/CCPA compliant" — https://useorigin.com/resources/blog/technical-overview' - id: ccpa conforms: true evidence: '"GDPR/CCPA compliant" — https://useorigin.com/resources/blog/technical-overview; DSAR form published at https://useorigin.com/legal/dsar-form' - id: sec-registered-investment-adviser conforms: true evidence: '"Regulated by the SEC" — technical overview; Form ADV 2A and Form CRS published at https://useorigin.com/legal/form-adv-2a and https://useorigin.com/legal/form-crs' - id: glba conforms: true evidence: GLBA privacy notice published at https://useorigin.com/legal/glba-notice - id: tls-transport-security conforms: true evidence: '"TLS 1.3 in transit, AES-256-GCM at rest with AWS KMS envelope keys" — technical overview; live probe confirmed TLSv1.3 + HSTS max-age 31536000 on useorigin.com (security/useorigin-domain-security.yml)'