Encryption
In transit: All connections to orbitpsa.com, our application surfaces, and our APIs use TLS 1.2 or higher. HTTP requests redirect to HTTPS at the edge. We publish HSTS with max-age=31536000; includeSubDomains; preload and have been submitted to the Chromium HSTS preload list (pending inclusion since May 21, 2026). Once distributed via Chrome auto-update, every modern browser will enforce HTTPS-only for orbitpsa.com and all subdomains on first visit — no man-in-the-middle window.
At rest: Customer data is stored on infrastructure providers (see Sub-processors below) using AES-256 encryption at rest. Database backups are encrypted, geographically redundant, and retention-limited.
Payment data: Orbit never stores raw card numbers. Stripe handles all payment instrument storage and PCI-DSS compliance. Orbit only retains tokenized references issued by Stripe.
Access controls
Production access is restricted to a named set of Orbit engineers, authenticated via SSO with mandatory multi-factor authentication. Production credentials are never embedded in code; secrets are managed through Vercel's encrypted environment-variable system.
Inside the Orbit application, every customer account supports role-based access controls. Audit-ready logging captures every privileged action (user invitations, permission changes, data exports, agreement edits, deletions) with timestamp and actor identity.
Customer-side:
- Mandatory MFA available on all plans
- SSO / SAML available on the Scale tier
- Granular role-based permissions out of the box
- Per-user session timeout and forced re-authentication
- Failed-login rate limiting and account lockout
Compliance posture
Orbit is a newer platform; we're being explicit about where each certification stands so buyers can make informed decisions.
| Standard | Current status | What it means |
|---|---|---|
| SOC 2 Type II | Architecture-ready, audit in progress | Controls are mapped to AICPA Trust Services Criteria. Formal attestation pending Q1 2027. |
| GDPR (EU) / UK GDPR | Compliant | Data processing addendum available on request; Article 28 terms standard for all customers. |
| CCPA / CPRA (California) | Compliant | California resident data rights honored via privacy policy. |
| HIPAA | HIPAA-aware configuration | Configurable per-client compliance tagging supports HIPAA workflows. BAAs reviewed case-by-case for healthcare MSPs. |
| PCI-DSS | Out of scope (Stripe handles) | Orbit never stores card data; payment processing is delegated to Stripe, which is PCI-DSS Level 1 certified. |
| ISO 27001 | On the roadmap | Scoping for 2027. |
Sub-processors
Customer data may be processed by the third-party services below. See the full list, purposes, locations, and data shared on the Sub-processors page.
- Vercel — application hosting and edge delivery (USA)
- Stripe — payment processing (USA, PCI-DSS Level 1)
- Resend — transactional email delivery (USA)
- Cal.com — demo scheduling (USA)
- Tawk.to — live chat (USA)
- Google Analytics 4 — anonymized site analytics (USA)
Data residency
Production data is stored in the United States by default. EU-based customers can request EU data residency on the Scale tier; contact sales for details and timing.
Incident response
We maintain a documented incident response plan. In the event of a security incident affecting customer data:
- Notification: Affected customers are notified within 72 hours of incident confirmation, per GDPR Article 33 timelines.
- Communication channel: Direct email to the customer's billing contact and security contact (if configured).
- Post-incident review: A written post-mortem is published for any incident classified Severity 1 or higher, including timeline, root cause, and remediation steps.
Report a suspected vulnerability to [email protected]. Public bug-bounty program is on the 2027 roadmap.
Business continuity
Orbit's production stack runs on Vercel's globally distributed edge network with automatic failover across regions. Database backups run every 15 minutes with point-in-time recovery available for the prior 30 days. Disaster recovery objectives:
- RPO (Recovery Point Objective): 15 minutes
- RTO (Recovery Time Objective): 4 hours for full regional failover
Employee security
Every Orbit employee with access to production data signs a confidentiality agreement, completes annual security awareness training, and uses company-issued, encrypted devices. Access is revoked within 4 hours of termination.
Responsible disclosure
We welcome reports from security researchers. Submit to [email protected] with details to reproduce. We commit to:
- Acknowledging your report within 2 business days
- Providing a triage assessment within 5 business days
- Crediting researchers in published advisories (with permission)
- Never pursuing legal action against good-faith research that follows this policy
Security contact
General security: [email protected]
Vulnerability reports: [email protected]
Compliance documentation requests: [email protected]
