Security Policy
How Orbit protects accounts, systems, product data, and customer content.
001 / Security Program
Orbit maintains administrative, technical, and organizational safeguards appropriate to the nature of the services and data processed.
002 / Access Controls
Access to production systems and customer data is restricted based on role, business need, authentication controls, and logging.
003 / Encryption
Orbit uses encrypted transport for supported services and appropriate encryption or provider-managed controls for stored data.
004 / Monitoring
We monitor for abuse, suspicious activity, service errors, and security events to protect users and infrastructure.
005 / Secure Development
Security is considered during development, dependency management, deployment, and incident response.
006 / Vulnerability Reports
Report security issues to support@orbitdev.org with enough detail to reproduce the issue. Do not access, alter, or exfiltrate data that is not yours.
007 / Responsible Disclosure
Orbit asks researchers to act in good faith, avoid privacy harm, avoid service disruption, and give us reasonable time to investigate before public disclosure.
008 / Limitations
No internet service can be guaranteed perfectly secure. Users should protect credentials, use strong authentication, and keep local devices updated.