Trust centre

The security posture behind the security platform.

Our customers hand us their attack surface. We treat that responsibility the way we'd want our own to be treated. This page documents how.

Encrypted in transit and at rest

All scan traffic uses TLS 1.3. Findings, evidence, and customer data are encrypted at rest with AES-256. Database backups run on a Daily, Weekly, and Monthly schedule; each backup is encrypted with a separate key.

No target credentials collected

Current assessments are unauthenticated (blackbox): CyberOrbit does not ask for, transmit, or store your target application's login credentials. Authenticated scanning is on the roadmap; when built, credentials will be handled via single-use in-memory handoff and never written to logs or persistent storage.

Tenant data isolation

Assessment jobs are processed sequentially with no cross-tenant data access path. Every finding and report is scoped to your organisation: no other customer or CyberOrbit staff can query your data. Findings carry a per-request SHA-256 proof hash so evidence integrity is independently verifiable.

Audit-grade logging

Every scanner action, every API call, every finding mutation is logged with actor, timestamp, target, and a SHA-256 proof hash. Logs are retained for the life of the engagement and provided to you on request.

Vulnerability management

We scan our own infrastructure with the same engine we sell. Critical findings on CyberOrbit infrastructure are remediated within 24 hours; high within 72 hours. We don't ship to production with a known critical.

Responsible disclosure

Found a security issue in CyberOrbit itself? Use the disclosure form below. We triage within one business day, fix it, and credit you in release notes. We don't pursue legal action against good-faith research.

Sub-processors

The full list of who touches your data.

We change this list before we change vendors, not after. Updates are announced via email to billing contacts at least 30 days before they take effect.

ProviderPurposeRegion
RailwayApplication hosting & infrastructureUS West · US East · EU West · Southeast Asia
Anthropic (Claude)AI-generated finding narrativesUnited States
OpenAIAI-generated remediation guidanceUnited States
GroqOpen-source model inference (validation)United States
PostgreSQL (managed)Customer data, findings, assessmentsUS West · US East · EU West · Southeast Asia
Redis (managed)Job queue, ephemeral stateUS West · US East · EU West · Southeast Asia
StripePayment processingUnited States
PostHogAnonymised product analyticsEuropean Union
Google (Gmail API)Transactional emailUnited States
Security FAQ

Questions from customers. Answered honestly.

Items marked Roadmap reflect our honest current state and what's coming next.

Do you require written authorization before running scans?

Yes. Every user must confirm they are authorised to test the target domain before a scan can be created. This confirmation is captured client-side in the assessment wizard today. We are rolling out server-side enforcement for all tiers so the confirmation is cryptographically logged against the assessment record, not just a checkbox on screen.

What happens if someone scans a target they don't own?

CyberOrbit blocks all private and internal IP ranges at the infrastructure level: scans cannot be directed at your own internal network or cloud metadata endpoints. For external targets, the platform relies on the authorisation confirmation above. Any misuse violates our Terms of Service and we will terminate the account. We log the target URL, timestamp, and acting user ID for every assessment started.

How is scan data handled and protected?

All traffic between your browser, our API, and our scan workers uses TLS 1.3. Findings, evidence, and all customer data are encrypted at rest with AES-256. Database backups run on a Daily, Weekly, and Monthly schedule; each backup is encrypted with a separate key. Scan workers operate in isolated job processes: your findings never share memory with another customer's assessment.

How long do you retain findings and reports?

Findings and reports are retained for the life of your subscription. On account closure, data is deleted within 30 days. You can export your full report (PDF + JSON) at any time from the dashboard. If you need earlier deletion, contact us via the legal form on our Privacy page.

Do you collect or store my application's login credentials for authenticated scanning?
Roadmap

Not today. Current assessments are unauthenticated (blackbox): CyberOrbit does not ask for, transmit, or store your target application's username, password, or session tokens. Authenticated (whitebox) scanning is on our roadmap. When built, credentials will be handled via single-use, in-memory handoff and will never be written to logs or persistent storage.

On our roadmap: Authenticated scanning: planned
Who can see my findings and reports?

Findings are scoped to your organisation. No other customer, no third party, and no CyberOrbit staff member can query your findings via the product. Our internal staff access policy requires a support ticket and explicit customer consent before any engineer can inspect customer data. MSP accounts have a separate visibility boundary: MSP admins see their clients' attributions, not raw findings.

Are scans isolated between customers?
Roadmap

Assessment jobs are queued and processed sequentially: one job runs at a time per worker. Your job does not share execution context with another customer's assessment. Finding data is strictly org-scoped at the database layer with RBAC enforced on every API endpoint. We do not use a separate container per assessment today; full container-level isolation is on the infrastructure roadmap.

On our roadmap: Per-assessment container isolation: on infrastructure roadmap
Can I limit what gets scanned (define a scope)?
Roadmap

Today, scans are directed at the single target URL you specify. The platform blocks private IP ranges, cloud metadata endpoints, and loopback addresses at assessment creation. A formal per-assessment scope allowlist (approved hostname/CIDR list with hard enforcement) is on the roadmap, especially relevant for MSP engagements.

On our roadmap: Scope allowlist: on our roadmap
Who are your sub-processors and where is my data held?

The full list is published in the Sub-processors section of this page and updated before any vendor change takes effect. Core customer data (findings, assessments) is hosted on managed PostgreSQL with one replica per region across US West, US East, EU West, and Southeast Asia. Scan worker infrastructure runs on Railway in the same four regions. Payment processing is handled by Stripe.

As an MSP, can I control which client environments are tested?
Roadmap

MSP admins have a dedicated dashboard showing all assessments attributed to each client, with the ability to view and manage them centrally. Today, any user with access can initiate a scan directly. A pre-scan approval gate, where an MSP admin must approve a scan request before it runs, is on our roadmap.

On our roadmap: MSP pre-scan approval gate: on our roadmap
How is my clients' data kept separate from other clients?

Every assessment, finding, and report is tagged with an organisation ID. All API endpoints enforce org-scoped RBAC: a user in Organisation A cannot read, modify, or delete data belonging to Organisation B under any circumstances. MSP admins can see attribution metadata for their own clients only.

Is CyberOrbit GDPR compliant?

Yes. CyberOrbit is GDPR compliant. We process personal data only as necessary to deliver the service, maintain a sub-processor list (published on this page), provide a Data Processing Agreement on request, and support data subject rights including access, rectification, and erasure. Our Privacy Policy details what data we collect, why, and how long we retain it. If you need a DPA before starting a trial, contact us via the Privacy page form.

What compliance frameworks does CyberOrbit itself comply with?
Roadmap

We are a pre-certification company. We do not currently hold SOC 2, ISO 27001, or equivalent certifications. We apply the same security practices we recommend to customers: encrypted data at rest and in transit, principle of least privilege, dependency scanning, and vulnerability remediation SLAs. SOC 2 Type I is on our near-term roadmap as we scale toward enterprise contracts.

On our roadmap: SOC 2 Type I: near-term roadmap
Can you provide a Data Processing Agreement (DPA) or NDA?

Yes. We will execute a mutual NDA and a DPA before any trial or paid engagement that requires one. Contact us via the legal form on our Privacy page and we will turn them around within two business days.

Found something? Tell us.

Security research on CyberOrbit is welcome and rewarded with credit in release notes. Triage within one business day. We don't pursue legal action against good-faith research.

0 / 5000

We triage within one business day. Good-faith research is never pursued legally.