Orbit Security Privacy
Trust & Transparency

Privacy Policy

Last Updated & Effective Date: September 26, 2026

1. Our Commitment to Your Privacy

At Orbit Security, we believe privacy is foundational to digital security. We operate under a strict principle of minimal data collection: we only collect what is strictly necessary to perform automated attack surface reconnaissance, generate white-labeled PDF audits for your agency, and manage your billing through Stripe. We do not sell, rent, monetize, or trade your personal data or your clients' domain audit findings to any third party or data broker under any circumstances.

2. Information We Collect & Zero-Server Scanning Guarantee

🛡️ Zero-Server Logging Guarantee for Browser Scans:

When you enter a domain into the Orbit Radar Terminal on our landing page or Fleet Command Center, the lookup is performed 100% within your client browser using RFC 8484 DNS-over-HTTPS. Orbit Security's web servers never receive, store, or log the target domains you analyze.

  • Account & Contact Information: Your agency name, contact email address, and agency website when you contact us, request a sample report, or subscribe.
  • Financial & Transaction Data: All payments are processed directly by Stripe (PCI-DSS Service Provider Level 1). Orbit Security never accesses, processes, or stores your credit card numbers, CVVs, or bank account credentials.
  • Third-Party DNS Resolvers: Browser-based DoH lookups query public resolvers provided by Google Public DNS and Cloudflare (Cloudflare 1.1.1.1 guarantees 24-hour log purges and zero IP-to-query correlation).
  • Static Hosting Telemetry: Standard web server connection logs (IP address, browser user-agent) generated transiently by GitHub Pages infrastructure.

3. How We Use Collected Data

Data collected is utilized strictly for the following operational objectives:

  • To execute automated DNS, DMARC, SPF, and subdomain takeover audits.
  • To compile and deliver co-branded, white-label PDF audit reports to agency operators.
  • To transmit automated security drift alerts when posture regressions or critical exposures are detected.
  • To process subscription billing and maintain merchant account compliance.

4. Cookies, Browser LocalStorage & Third-Party Trackers

Orbit Security adheres to strict privacy-first standards:

  • Zero Advertising Tracking Cookies: We do not deploy third-party advertising cookies, conversion tracking pixels (e.g., Meta Pixel, Google Ads), or invasive behavioral session recording software (e.g., Hotjar, FullStory).
  • HTML5 LocalStorage Usage: Our multi-domain Fleet Command Center (fleet.html) utilizes browser window.localStorage under the key orbit_fleet_registry_v2 solely to persist your client domain registry locally on your device between browser sessions. This data is never synchronized to Orbit Security servers. You can permanently delete this local data at any time by clearing your browser cache or clicking "Clear Fleet" in the application.
  • Client-Side PDF Compilation: All executive PDF deliverables generated via the "Export Branded PDF" feature are compiled purely in client RAM using pdf-lib. No client logos, audit scores, or corporate identities are uploaded to third-party rendering clouds.

5. GDPR & CCPA/CPRA Consumer Rights

Under the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), you retain the following statutory rights regarding your personal information:

  • Right to Know & Access: The right to request a copy of the specific pieces of personal information we hold about you.
  • Right to Deletion: The right to request immediate purging of your contact records, domain history, and billing profile.
  • Right to Non-Discrimination: We will never deny services, charge different rates, or degrade service quality for exercising privacy rights.
  • Opt-Out of Domain Audits: Any domain owner may request permanent exclusion from automated scanning by contacting our security team.

To exercise any of these rights, email carsonmail009@gmail.com with the subject line "Privacy Rights Request". Requests are verified and fulfilled within 10 business days.

6. Data Security & Encryption Standards

All transmission of data across our infrastructure is secured using Transport Layer Security (TLS 1.3). Internal client configurations and fleet registries are restricted and encrypted at rest using AES-256.

7. Privacy Contact

Direct all data governance, privacy, and compliance inquiries to:
Orbit Security Operations
Attn: Carson Haynes | Privacy Officer
Email: carsonmail009@gmail.com