Skip to content
Orbit
How it works Flows Orbit Core Pricing Request early access

Legal

Security & Trust Statement

What we do to protect your community’s information — and what we will never do with it.

The Orbit SAAS Pty Ltd (“Orbit”) · Effective June 2026 · Version 1.0

  • Built on Microsoft Azure
  • Encrypted, everywhere
  • Every organisation’s data is isolated
  • Sign-in security
  • Payments you can trust
  • No keys under the doormat
  • A complete audit trail
  • Security in how we build
  • You stay in control
  • Report a security issue

Our promise

  • Your information belongs to you — not to us, and never to anyone else.
  • We never sell your data or share it with third parties for their own use.
  • Security is built in, not bolted on — from the infrastructure up.
  • Everything significant is logged, so there is always an answer to “who did what, and when?”

What we will never do

  • Sell or rent your information. To anyone. Ever.
  • Share your information with third parties for their own marketing or purposes.
  • Store your card numbers.
  • Let one organisation see another organisation’s data.
  • Make changes that weaken these commitments without telling you.

Built on Microsoft Azure

Orbit runs entirely on Microsoft Azure, the same enterprise cloud platform trusted by governments, banks and hospitals. Your data is hosted in Australian data centres with Microsoft’s physical security, redundancy and infrastructure protections underneath everything we build.

Encrypted, everywhere

Your information is encrypted in transit — every connection to Orbit uses HTTPS/TLS, with no unencrypted access — and encrypted at rest, covering both the database and all stored files. Photos and documents are kept in private storage that cannot be accessed from the open internet; every download is checked against who you are and what you are allowed to see.

Every organisation’s data is isolated

Each organisation on Orbit (each “Planet”) operates in its own secure space. Isolation is enforced at the platform’s core: every single request is checked against your membership, and data queries are automatically filtered so one organisation can never see another’s information. Your Planet’s coach applications, member records and conversations are visible to your Planet’s authorised staff — and no one else’s.

Sign-in security

Passwords are never stored as readable text — only as salted, one-way cryptographic hashes using Microsoft’s identity framework. Sessions use hardened, secure cookies. Email verification links are digitally signed and time-limited, so they cannot be forged or reused. Public forms are protected by Cloudflare Turnstile bot detection and rate limiting, which keeps automated abuse out while staying invisible to genuine users.

Payments you can trust

All payments are processed by Stripe, a global payment provider certified to PCI-DSS Level 1 — the highest standard in the payments industry. Card details go directly from your browser to Stripe. Orbit never sees, transmits or stores card numbers. Each organisation’s payments flow through its own dedicated Stripe account, keeping its funds cleanly separated.

No keys under the doormat

Credentials, API keys and signing keys are stored in Azure Key Vault, a hardened, access-controlled secrets store — never in code or configuration files. Wherever possible, Orbit’s systems authenticate to each other using Azure Managed Identities, which means there is no long-lived password to steal in the first place. Every access to a stored secret is itself logged.

A complete audit trail

Every significant action on the platform — a form submitted, a payment processed, an approval given — is recorded in an append-only audit log: who acted, what happened, and exactly when. Append-only means records can be added but never edited or quietly removed. Access to audit data is restricted to authorised platform administrators, and that access is itself controlled and recorded.

Security in how we build

Security is part of our engineering process, not an afterthought. Every change that touches identity, payments, messaging or external integrations goes through a mandatory security review before release. Access follows the principle of least privilege — people and systems get the minimum access needed to do their job. Architecture decisions are formally documented and reviewed, so security choices are deliberate and traceable.

You stay in control

  • You choose what appears on your profile and what is shared when you join an organisation — nothing is shared automatically.
  • You control your notifications by category and channel, including quiet hours.
  • You can opt out of opportunity suggestions and platform news at any time.
  • You can request a copy of your information, a correction, or deletion — see our Privacy Policy for how.

Report a security issue

We are happy to talk about security — it is a feature, not a secret. If your organisation needs more detail for its own due diligence, contact us and we can provide further information about our security practices.

If you believe you have found a security issue, please report it to hello@my-orbit.com.au with the subject line “Security disclosure”, and we will respond promptly. See our security.txt for the machine-readable version of this contact.

The Orbit SAAS Pty Ltd — hello@my-orbit.com.au

Want to know what this means for your personal information specifically? Read our Privacy Policy.

Orbit

Helping community organisations grow — without growing the admin.

How it works Flows Orbit Core Pricing

my-orbit.com.au · © 2026 Orbit · Built in Australia

Privacy Policy Security & Trust