What Orbit protects today—and what is still beta.
Orbit is designed for compliance readiness, but is not SOC 2 certified, ISO certified, or presented as GDPR/DPDP certified.
Implemented controls
Production secrets stay in hosting-provider environment storage. API access uses expiring server-side sessions. Passwords are salted and hashed with scrypt. Database access uses parameterized SQLAlchemy queries. Admin APIs require a separate server-side credential.
- Explicit production CORS origin
- Consent gates for introductions and application actions
- Private agent memory separated from matchable profile data
- Audit records for material beta actions
- Signed, expiring organization workspace links
- Contact information hidden until an introduction is accepted
Infrastructure
The current beta uses Vercel for the frontend, Render for the API, and managed PostgreSQL. TLS is provided at public endpoints. Render free instances may cold-start and are not an enterprise availability commitment.
Known gaps
Independent penetration testing, automated backup-restore evidence, enterprise SSO/SCIM, formal incident on-call, email verification, automatic payment webhooks, and full WebRTC hosted voice are not complete. Do not use the beta for highly sensitive or regulated data.
Report a vulnerability
Email immanobharath21@gmail.com with reproduction steps and impact. Please avoid accessing other users’ data or disrupting the service while testing.
Last updated: 2 September 2026 · Contact: immanobharath21@gmail.com