FAQ

Questions, answered

Why data that should move does not, what we build, and how we handle it. If your question is not here, ask us directly.

The problem

Data is the most valuable asset most organizations already own. The problem is not a lack of data, it is that the data cannot move.

Why doesn't our data move, when we already have all of it?

Data is the most valuable asset most organizations already own. The problem is not a lack of data. The problem is that data cannot move. Eight root causes hold it in place: fear, cost, legacy technology, governance gaps, classification, organizational boundaries, complexity, and inertia. These are organizational, political, and cultural problems, not technology problems in isolation.

Why haven't point solutions fixed this?

Because point solutions fix one dimension while ignoring the others. A tool that solves the technical transport problem does nothing about the governance gap that makes the default answer no, or the classification practice that keeps data at a level where it cannot inform the decision. Fixing one of eight causes leaves the data exactly as stuck as it was.

Fear: why do organizations refuse to share data they already own?

Fear of sharing, exposure, liability, and getting it wrong. When the cost of a mistake is visible and the benefit of sharing is diffuse, organizations default to restriction.

Cost: why is integrating data across systems so expensive?

Moving, integrating, and maintaining data across heterogeneous systems is expensive, and technical debt compounds over time.

Legacy technology: why do point-to-point integrations keep breaking?

Decades of point-to-point integration create brittle, unmaintainable architectures that break constantly.

Governance gaps: why is the default answer to a data access request no?

With no policy framework for who can access what, the default answer is nobody. Data stays locked to avoid the appearance of unauthorized disclosure.

Classification: how does over-classification block decisions?

Over-classification and misclassification prevent appropriate sharing. Data that could safely inform decisions at lower levels remains inaccessible.

Organizational boundaries: why can't agencies and allies share across boundaries?

Agencies, departments, mission partners, and allies often lack the trust, authority, or mechanism to share data across their boundaries.

Complexity: why can't we find the data we already have?

Nobody knows what data they have, where it lives, or how to use it. Without a discoverable, indexed catalog, organizations cannot act on what they cannot find.

Inertia: why do initiatives stall even after the technology works?

We have always done it this way. Cultural resistance to changing how data moves is often the final barrier, standing even after every technical obstacle is cleared.

Our approach

What is a governed data fabric?

Governance and data flow are inseparable. You cannot have fast, useful data movement without rigorous control over who sees what, under what conditions, and for what purpose. You cannot have meaningful governance without the technical means to enforce policy at scale, across boundaries, in real time. A governed data fabric unifies both rather than treating them as two projects.

Which direction does data flow?

Bidirectionally by design. Intelligence from the edge flows up for analysis, enriched insight flows back down into operational tools, analyst output flows into command decision systems, and customer tools receive data back in the formats they already use.

Do we have to modernize our infrastructure first?

No. Orbis deploys where the data is: modern cloud-native, twenty-year-old on-premises, or intermittently disconnected tactical edge. AI capability reaches environments other vendors have written off as too complex or too constrained, so the analyst at a forward location gets the same quality of assistance as the analyst at headquarters.

Does this require a multi-year transformation program?

No. Each offering delivers value independently. There is no multi-year transformation program before value, no heavyweight architecture imposed, and no requirement to stop operating while you modernize.

How does Orbis decide where AI belongs and where it doesn't?

Risk-informed judgment is the differentiator. Orbis knows when AI accelerates a decision cycle and when it introduces unacceptable risk, and will tell you which is which. That judgment comes from practitioners who have carried the consequences of the decision, not from a product roadmap.

What is CODL, the Common Operational Data Layer?

CODL is the standard for routing the right data to the right operators across nodes, domains, and partners. It is a technical term, used when the audience is technical.

About Orbis

What does Orbis Operations do?

Orbis Operations delivers sovereign intelligence and decision capabilities to the U.S. Government and its allies, converting complex information and operational systems into decisive outcomes. Headquarters are in McLean, Virginia.

Is Orbis a consulting firm or a systems integrator?

Neither. Every engagement is staffed by practitioners who have operated at the mission edge, and the work is delivering capability rather than advising on it or assembling someone else's components.

When was Orbis founded and where do you operate?

Orbis was founded in 2008 and is headquartered in McLean, Virginia. There are three offices: Washington, DC; Canberra, Australia; and Taipei, Taiwan.

Who does Orbis work with?

The U.S. Government, allied nations, and critical enterprises.

How do we get in touch?

Email impact@orbisops.com, or request a briefing through the contact page.

Products

What is Catalyst?

Catalyst is a transport-agnostic, declarative data-movement and transformation platform for moving disparate data across network and domain boundaries. Describe your pipeline in YAML, deploy it live to any node in your fleet, and Catalyst moves the data durably, observably, and under policy.

How does a Catalyst node actually run?

The runtime unit is a single Go binary with no external dependencies. It ingests from a source, transforms through a pipeline, stores durably, and pushes to multiple sinks. Nodes dial outward to the fleet manager and hold the session, so no node exposes an inbound control port. It is air-gap-native, built for the contested edge rather than retrofitted to it.

Can we deploy changes without taking nodes down?

Yes. Programs deploy live to running nodes with no image rebuild or restart, and reconcile automatically on node boot. Registry commands can populate a node's artifact store directly on disk with no fleet manager present, and a single flow can run offline. Deployment state survives restarts.

What happens to data when a Catalyst pipeline is under load?

Every inter-stage handoff is a durable bounded queue with selectable strategies and retention limits, so the system degrades gracefully instead of dropping data or buffering without bound.

How does Catalyst handle sensitive fields in a pipeline?

Content policy operators redact sensitive patterns and filter fields. They terminate the raw payload, so unredacted bytes cannot pass the policy stage.

Can we add our own integrations to Catalyst?

Yes. Any stage can be an out-of-process plugin over a versioned contract, so custom or NDA'd integrations stay out of the core binary and a plugin crash cannot take down the node. Roughly three dozen first-party plugins ship across all five stage roles.

What is Pulse?

Pulse is a multi-source data collection platform. Clients submit collection requests over HTTP, Pulse dispatches them to distributed workers, tracks status, and delivers results to the caller's configured destination.

Where can Pulse be deployed?

To commercial cloud, or to IL5-hardened infrastructure for on-premises, air-gapped, and DoD IL5 and IL6 customers. Packaging tiers are Signal, Bronze, Silver, Gold, and Full Spectrum.

What is Discovery?

Discovery is a single secure workspace where analysts research a question, collect and analyze what they find, and write it up, without bouncing between a dozen tools or revealing who is doing the looking. It hides the analyst's identity and intent from the targets under investigation.

What can an analyst do in Discovery?

Four task types: General Search, Translation, Person Search, and Social Media Collection. Projects are the top-level workspace, and the project name and description feed the AI as context, so results and suggested questions track the analyst's actual focus.

How does General Search work?

It queries multiple sources in parallel and returns a structured summary with inline citations. Summaries follow analytic writing practice: lead with the main finding, note where evidence is insufficient, and never fabricate an answer the sources do not support. Suggested questions are grounded in the analytic thinking principles Orbis teaches in its own training programs, and the analyst accepts or rejects each one.

What does Translation support?

PDF or plain text, returning both full translated text and a side-by-side segment view. It supports any language and domain terminology, and honors a per-project terminology guide.

What does Person Search do?

It maps an individual's digital footprint from a single selector, one to three hops deep, and presents findings the analyst reviews and accepts or rejects individually.

What does Social Media Collection cover?

Ten platforms. Posts are presented in a filterable feed, and analysts can interrogate the whole collected corpus in a chat interface with numbered inline citations. Confirmed conclusions save to a findings repository that survives clearing the chat or re-running collection, and feed the project report.

How does reporting work in Discovery?

Reports generate automatically as tasks complete, including a key takeaways section, and are fully editable. The report is both a starting point for the finished product and a complete log of the research performed.

How does Discovery keep the analyst from being identified?

Secure browsing routes every source link through remote browser isolation. The page executes on isolated infrastructure, never on the analyst's machine or network. The third-party site sees only an infrastructure IP, with no exposure of the analyst's identity or location. No software installation is required, and sessions delete fully when the tab closes.

Security and data

What certifications do the products hold?

Products are not individually certified. Discovery runs on infrastructure holding ISO 27001, ISO 27701 and ISO 27018, SOC 2 Type II, and FedRAMP Moderate, and customers inherit that posture without managing an on-premises or private-cloud deployment. Discovery is pursuing its own ISO 27001 certification. Everything else is built to support the accreditation boundary you already hold.

How is our data encrypted?

At rest with AES-256 and in transit with TLS. Object storage is further protected with project-specific keys, so content decrypts only inside that project, by its owner.

Is our data separated from other customers?

Yes. No data is shared across customers, and data is isolated between projects even inside a single organization.

Can Orbis staff see our data?

No. Orbis staff cannot access customer data, including for support and troubleshooting.

What happens when we delete a project?

Deleting a project destroys the decryption key, rendering the data permanently inaccessible.

How does authentication work?

Authentication uses OIDC. Customers with an identity provider integrate their own SSO; customers without one get accounts in a managed tenant. Authorization is role-based within the platform.

Who can see a project today?

A project is accessible only to the person who created it. Project-level permissions and role-based access control across an organization are on the roadmap and are not shipped, so there is no team sharing within a project today.

Is our data used to train AI models?

No. Customer data is never used to train AI models. External AI services are enterprise accounts under contractual guarantees that Orbis retains ownership and control and that the vendor cannot train on the data. External requests carry the task input plus the project title and description, and nothing identifying the customer. User actions are logged; user-entered content is not.

Can we avoid external sources entirely?

Yes. For general search, you can choose to work exclusively with your own uploaded sources and skip external sources altogether.

Solutions Forged from Experience

Governance and data flow, built together

Seven of the eight root causes are organizational rather than technical, which is why governance and data flow have to be one capability rather than two projects. Each offering delivers value on its own, with no multi-year transformation before you see any.