Skip to main content
Trust Center

Everything your procurement team needs.

The single URL to send to your security, legal, and procurement teams. Security posture, privacy policy, compliance roadmap, sub-processors, terms, SLA, and live status — all linked from one place. Documentation available on request.

The six pillars

Security

Encryption posture (TLS 1.2+ in transit, AES-256 at rest), access controls (SSO + MFA mandatory in production), incident response (72-hour notification per GDPR Article 33), and the disaster-recovery posture (RPO 15min, RTO 4hr).

  • TLS 1.2+ in transit · AES-256 at rest
  • SSO + MFA required for production access
  • 72-hour breach notification
  • Backups every 15 minutes, point-in-time recovery

Privacy

GDPR + CCPA-compliant privacy policy. What we collect by audience (visitors / prospects / customers / end-users), legal bases, retention, user rights (access, correction, deletion, portability, restriction, objection, opt-out), and Standard Contractual Clauses for international transfers.

  • GDPR + UK GDPR + CCPA compliant
  • DPA available on request
  • User-rights response: 30 days (45 for CCPA)
  • SCCs + EU-US Data Privacy Framework

Compliance posture

Explicit status of every certification — what's done, what's in flight, and what's on the roadmap. No vague claims; if it's not certified, we say so plainly.

  • SOC 2 Type II — architecture-ready, audit Q1 2027
  • GDPR + CCPA — compliant today
  • HIPAA-aware configuration
  • ISO 27001 — scoping for 2027

Sub-processors

Full GDPR Article 28 disclosure of every third-party service that processes Customer Data, with purpose, data category, region, and certifications. 30-day notice before any new sub-processor is added.

  • 10 sub-processors disclosed today
  • Purpose + region + certifications per vendor
  • 30-day notice on additions
  • Quarterly review cadence

Terms & SLA

Subscription terms, 99.9% monthly uptime target, acceptable-use policy, Customer Data ownership (you keep yours), IP, warranties, liability cap at 12 months of fees, and Delaware governing law. Negotiated MSAs available for procurement.

  • 99.9% monthly uptime target
  • Customer retains all Customer Data rights
  • Negotiated MSA for procurement on request
  • Delaware law · informal dispute resolution first

Live service status

Real-time operational state of every Orbit component (web app, marketing site, API, email, payments, Tuesday AI). Customers automatically receive incident notifications. Severity 1 incidents trigger a written post-mortem.

  • Live status across 6 components
  • RPO 15 minutes · RTO 4 hours
  • Auto-notify on Severity 1+
  • Public post-mortems for major incidents

Procurement documentation

Documentation that your procurement, security, or legal team typically requests during evaluation. All available on request. Most documents return in under 24 hours.

Data Processing Addendum (DPA)

GDPR Article 28 contract. Pre-signed and ready to attach to your MSA.

Email [email protected]

Master Subscription Agreement (MSA)

Negotiated alternative to the click-through Terms.

Email [email protected]

Security Questionnaire (SIG / CAIQ)

Pre-filled responses for SIG-Lite and CAIQ v4.0 covering controls, data handling, and BCP/DR.

Email [email protected]

Service-Level Agreement (SLA)

Written SLA with service-credit calculation. Scale tier.

Email [email protected]

Insurance Certificate

Current cyber + E&O coverage summary.

Email [email protected]

Business Associate Agreement (BAA)

Reviewed case-by-case for healthcare MSPs.

Email [email protected]

Security inquiries

[email protected]

Vulnerability reports, security questionnaires, BAA / DPA. Acknowledgment within 2 business days.

Privacy inquiries

[email protected]

GDPR + CCPA rights requests, sub-processor objections, data-subject access. Response within 30 days.

Procurement / legal

[email protected]

MSA, SLA, SOW, insurance certificates, BAA, DPA. We route to the right team within one business day.