Orbit public policy draft
Security & responsible disclosure
Orbit is being built with privacy boundaries, role-based access and secure delivery as product requirements—not as afterthoughts.
Important: This page describes the current direction of the product, not a security certification. A public security contact and final disclosure process must be added before external launch.
Current safeguards
Orbit’s current products use organisation-scoped access, role controls and protected report states. The learning environment has additional controls around uploaded learning content and package isolation.
Responsible research
Please do not access data that is not yours, disrupt services, use social engineering, or attempt to exploit a suspected issue. Keep proof-of-concept testing minimal and protect any information you encounter.
Reporting a concern
Until a public disclosure contact is published, authorised users should report security concerns to the project contact who provisioned their Orbit access. Before external launch, Orbit will publish a dedicated contact, scope and response process here.
What to include
Describe the affected area, steps to reproduce, expected and actual behaviour, potential impact, and any evidence needed to understand the issue. Do not include passwords, secrets or personal data unless essential and securely requested.