Security at Orbyt
Last updated: June 16, 2026
1. Overview
Orbyt ("Orbyt", "we", "our", or "us") provides a calendar, scheduling, and productivity platform. Protecting the confidentiality, integrity, and availability of your data is fundamental to our service. This page describes the technical and organizational measures we use to safeguard customer data. It is provided for transparency and informational purposes only and does not create any warranty, representation, contract, or guarantee, express or implied. Our Terms & Conditions and Privacy Policy govern the legal relationship between you and Orbyt and, in the event of any conflict, control over this page.
2. Infrastructure & Hosting
Orbyt's application is hosted on globally distributed edge infrastructure operated by Cloudflare, with database, authentication, file storage, and serverless compute provided by Supabase (which runs on Amazon Web Services). These providers maintain industry-recognized certifications, including SOC 2 Type II and ISO/IEC 27001, and operate physically secured, access-controlled data centers with redundant power, networking, and environmental controls.
Production systems are logically segregated from development and staging environments. Administrative access to production infrastructure is restricted to a limited number of authorized personnel, requires strong authentication, and is logged.
3. Encryption
In transit. All traffic between your browser or device and Orbyt is encrypted using TLS 1.2 or higher with modern cipher suites. HTTPS is enforced across the application, and HTTP Strict Transport Security (HSTS) is enabled on our primary domain.
At rest. Customer data stored in our database and object storage is encrypted at rest using AES-256 or equivalent, managed by our infrastructure providers. OAuth refresh tokens used to connect third-party calendars are stored in secured server-side storage and are never exposed to client-side code.
4. Authentication & Access Control
User authentication is handled by Supabase Auth and supports email/password, magic links, and OAuth providers such as Google. Passwords are never stored in plaintext; they are hashed using industry-standard algorithms. Sessions are managed via short-lived JWT access tokens and rotating refresh tokens.
Inside the application, we enforce Row-Level Security (RLS) policies at the database layer so that a given user can only read or modify rows that belong to them or to workspaces they are a member of. Server-side logic additionally validates permission on every privileged operation. Internal administrative access to customer data is limited to a need-to-know basis, requires multi-factor authentication, and is logged.
5. Calendar & Third-Party Integrations
When you connect a Google, Microsoft, or Apple calendar, Orbyt uses standard OAuth 2.0 flows and stores only the access and refresh tokens needed to perform the actions you authorize (such as reading events, creating events, or detecting conflicts). You may revoke access at any time from your account settings or directly from the provider's security dashboard, and we will delete the associated tokens.
Use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to train generalized or large language AI/ML models.
6. Payments
Subscription billing and, where enabled, marketplace/booking payments are processed by Stripe, a PCI-DSS Level 1 certified payment processor. Orbyt does not store full payment card numbers, CVCs, or bank account credentials on its own servers. Payment tokens and minimal metadata (such as the last four digits of a card and expiration date) may be stored to display account information.
7. Sub-processors
Orbyt relies on a limited number of vetted sub-processors to operate the service, including Supabase (database, authentication, storage, edge functions), Cloudflare (edge hosting, content delivery, DDoS mitigation), Stripe (payments), and the calendar providers you choose to connect. Each sub-processor is bound by contractual confidentiality and data-protection obligations consistent with applicable law. A current list of material sub-processors is available on request at privacy@oneorbyt.com.
8. Application Security Practices
- Server-side input validation using schema validation (Zod) on user-supplied data.
- Parameterized database queries to prevent SQL injection.
- Content Security Policy, secure cookies, and standard browser hardening headers.
- Automated dependency scanning and prompt patching of known high/critical vulnerabilities.
- Principle of least privilege for service accounts, API keys, and internal roles.
- Secrets stored in encrypted secret managers, never in source code or client bundles.
- Code review of changes prior to deployment to production.
9. Monitoring, Logging & Backups
We maintain application and infrastructure logs to support troubleshooting, abuse detection, and security investigations. Logs are retained for a limited period consistent with operational and legal needs. Our database provider performs automated backups with point-in-time recovery capabilities. Backups are encrypted and stored in geographically distributed locations.
10. Vulnerability Management & Responsible Disclosure
We welcome reports from security researchers. If you believe you have discovered a security vulnerability in Orbyt, please email security@oneorbyt.com with a clear description, steps to reproduce, and any supporting material. We ask that you:
- Give us a reasonable time to investigate and remediate before public disclosure.
- Avoid privacy violations, data destruction, service degradation, or social engineering.
- Only test against accounts you own or have explicit permission to access.
- Do not execute denial-of-service attacks or automated high-volume scanning.
Acting in good faith and in accordance with this policy, we will not pursue or support legal action against you for your research. Orbyt does not currently operate a paid bug-bounty program, and submission does not entitle you to any payment.
11. Incident Response
Orbyt maintains an internal incident response process covering detection, containment, eradication, recovery, and post-incident review. In the event of a confirmed personal data breach that triggers notification obligations under applicable law (such as GDPR Article 33 or U.S. state breach-notification statutes), we will notify affected customers and, where required, regulators within the timeframes mandated by law. Notifications will describe, to the extent known, the nature of the incident, the categories of data involved, and the steps we have taken or recommend you take in response.
12. Data Retention & Deletion
We retain customer content for as long as your account is active and for a limited period thereafter, as described in our Privacy Policy. You can delete tasks, projects, calendar connections, and other content from within the product at any time. To request deletion of your account and associated personal data, contact privacy@oneorbyt.com. Certain records (e.g., billing and tax records) may be retained as required by law.
13. Your Responsibilities
Security is a shared responsibility. To help keep your account safe, you should:
- Use a strong, unique password and enable any available multi-factor authentication on your identity provider.
- Keep your devices, operating systems, and browsers up to date.
- Promptly revoke access for team members or integrations you no longer use.
- Notify us immediately if you suspect unauthorized access to your account.
14. Compliance
Orbyt is designed with privacy and security best practices in mind and supports customer compliance with regulations such as the EU General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act (CCPA/CPRA). We rely on our infrastructure providers' independently audited certifications (including SOC 2 Type II and ISO/IEC 27001) for underlying platform controls. Unless expressly stated in a signed written agreement, Orbyt itself does not claim to be independently certified under any particular standard, and nothing on this page constitutes such a certification.
15. No Warranty
No system, control, or process can guarantee absolute security. The measures described on this page are provided on an "as is" basis and are subject to change as the service evolves, threats evolve, and our providers update their own controls. Except as expressly set out in our Terms & Conditions or a separate signed agreement, Orbyt disclaims all warranties, express or implied, regarding the security of the service, including any implied warranties of merchantability, fitness for a particular purpose, and non-infringement. Your use of the service is subject to the limitations of liability set out in our Terms & Conditions.
16. Changes to this Page
We may update this page from time to time to reflect changes to our practices, providers, or the service. The "Last updated" date at the top indicates when this page was most recently revised. Material changes that affect the security of customer data will be communicated in accordance with our Terms & Conditions and Privacy Policy.
17. Contact
Security questions, vulnerability reports, or compliance inquiries: security@oneorbyt.com. Privacy and data-protection inquiries: privacy@oneorbyt.com.
