1. Our Commitment
Security is foundational to Orbitova. We protect your data with industry-standard practices.
2. Infrastructure Security
- Hosted on Supabase (SOC 2 Type II certified infrastructure)
- Data encrypted at rest using AES-256
- Data encrypted in transit using TLS 1.3
- Regular automated backups
3. Payment Security
- Payments processed by Razorpay (PCI DSS Level 1 certified)
- We never store credit/debit card numbers
- All transactions encrypted end-to-end
4. Access Control
- Row-level security on all database tables
- Each organization's data is completely isolated
- Role-based access control within organizations
- Session tokens expire automatically
5. Authentication
- Email + password with secure hashing (bcrypt)
- Google OAuth 2.0 support
- Magic link (passwordless) authentication
- Sessions invalidated on logout
6. Reporting Security Issues
If you discover a security vulnerability, please report it responsibly:
Email: hello@orbitova.in
Subject: "Security Vulnerability Report"
We will acknowledge within 24 hours and provide updates every 48 hours. Please do not publicly disclose the issue until we have resolved it.
7. Bug Bounty
We appreciate responsible disclosure. Significant findings may be eligible for recognition or reward.