Trust & Security

Built for the most demanding security requirements

Orbis applies security-first principles across every product - from managed commercial services to fully air-gapped sovereign deployments. Every architecture decision prioritizes zero trust, auditability, and defense in depth.

Compliance posture

Orbis products are not individually certified. Discovery runs on infrastructure that holds the certifications below, and customers inherit that posture without standing up and managing their own on-premises or private-cloud deployment. Everything else is built to support the accreditation boundary you already hold. Documentation is available through the Orbis Trust Center.

ISO 27001

Infrastructure certified

Discovery runs on infrastructure holding ISO 27001. Discovery is pursuing its own ISO 27001 certification.

ISO 27701 and ISO 27018

Infrastructure certified

Privacy information management and protection of personally identifiable information in public cloud, held at the infrastructure layer Discovery runs on.

SOC 2 Type II

Infrastructure audited

The infrastructure Discovery runs on is audited to SOC 2 Type II.

FedRAMP Moderate

Infrastructure authorized

The infrastructure Discovery runs on holds FedRAMP Moderate authorization. This is an inherited posture, not a per-product authorization.

Your accreditation boundary

Built to support

Where a product is not covered by inherited infrastructure certification, it is built to support the accreditation boundary you already hold rather than asking you to extend it.

Defense Base Act Coverage

Active

Orbis maintains Defense Base Act coverage for personnel deployed in support of government contracts overseas.

Architecture Principles

Security is not layered on after the fact. These principles are load-bearing assumptions in every design decision.

Zero Trust by Default

Every request - whether from a human operator, a service, or a partner organization - is authenticated, authorized, and audited. No implicit trust is granted based on network location or prior session state. Least-privilege access is enforced at the data layer, not just the perimeter.

Encryption and key scope

Data is encrypted at rest with AES-256 and in transit with TLS. Object storage is further protected with project-specific keys, so content decrypts only inside that project, by its owner. Orbis staff cannot access customer data, including for support and troubleshooting. Deleting a project destroys the decryption key, rendering the data permanently inaccessible.

Air-Gap Compatible (Catalyst)

Catalyst is designed from the ground up to operate without internet connectivity. The full Catalyst deployment runs in fully disconnected environments with no phone-home requirement and no cloud-resident data path. Discovery and Pulse are managed commercial services and do not offer air-gapped deployments.

Audit Everything

Every data access, policy decision, and administrative action is immutably logged. Audit logs are tamper-evident, exportable to SIEM platforms, and retained according to customer policy. Security teams have full visibility into who accessed what data, when, and why - in real time and historically.

Data protection across every deployment model

Orbis applies strict data protection principles across all Orbis products - but the implementation reflects each product's deployment model.

Catalyst can deploy entirely within customer-controlled infrastructure. In self-hosted and air-gapped deployments your data never leaves your environment, no telemetry is sent to Orbis, and there are no outbound data paths. For air-gapped deployments, the installer is fully self-contained - no internet access is required after delivery, including for updates and license validation.

Discovery and Pulse are managed commercial services operated by Orbis on your behalf. Customer data is never used for model training, never shared across customers, and is protected under contractual data handling commitments. Query privacy is enforced at the application layer - your investigations remain yours.

Customer data trainingNever
Cross-customer data accessNone
TelemetryNone
Key custody (Catalyst)Customer only
Air-gap supportCatalyst
Documentation

Access the Trust Center

Security questionnaires, audit reports, penetration test summaries, and detailed architecture documentation are available through the Orbis Trust Center. NDA-protected materials are available to qualified program offices upon request.