# Security & Trust: Encryption and Data Protection

> How MyOrbit protects your data: encryption in transit and at rest, access controls, monitoring, and how to report a security issue.

Canonical page: https://myorbit.ai/security

---

## Security & Trust Center

Last Updated: August 12, 2026 • Version 1.1.1

At MyOrbit, security isn't an afterthought—it's the foundation of everything we build. We use security measures including encryption and automated monitoring to protect your data and privacy.

This page outlines our security practices and our commitment to keeping your data safe.

### Table of Contents

1. How We Encrypt Your Data
2. Secure Infrastructure
3. Compliance & Certifications
4. Access Controls
5. Security Monitoring
6. Incident Response
7. Data Protection
8. Responsible Disclosure
9. Best Practices for Users
10. Security Contact

### 1\. How We Encrypt Your Data

**What we do not claim:** MyOrbit does not offer end-to-end encrypted or zero-access messaging. We are technically able to access message content, and we do so where our safety, moderation, legal or support processes require it. Please do not read anything on this page as a promise that we cannot see your messages.

#### Data at Rest

- **AES-256 Encryption:** Industry-standard encryption algorithm for stored data
- **Managed Keys:** Encryption keys held in a managed key service with restricted access
- **Safety Scanning:** Real-time content moderation for user protection

#### Data in Transit

- **TLS 1.3:** All data transmitted over encrypted connections
- **HSTS Enforcement:** Forces HTTPS connections

### 2\. Secure Infrastructure

#### AWS Infrastructure

MyOrbit is hosted on Amazon Web Services (AWS), one of the world's most secure cloud platforms:

- **AWS Security Standards:** Benefit from AWS's enterprise-grade infrastructure
- **Multiple Availability Zones:** Redundancy across multiple availability zones
- **DDoS Protection:** AWS Shield for distributed denial-of-service mitigation
- **Auto-Scaling Security:** Infrastructure scales to handle traffic spikes

#### Network Security

- **Web Application Firewall (WAF):** Blocks malicious traffic
- **CloudFront CDN:** DDoS mitigation and fast, secure content delivery
- **VPC Isolation:** Private network segments for sensitive operations
- **IP Whitelisting:** Restricted access to administrative systems

### 3\. Compliance & Certifications

#### Compliance Status

- **SOC 2 Type II:** Planned
- **GDPR:** Our practices are designed to meet the requirements of the EU General Data Protection Regulation
- **CCPA/CPRA:** Designed to meet the requirements of the California Consumer Privacy Act
- **COPPA:** Designed to meet the requirements of the Children's Online Privacy Protection Act

#### Industry Standards

- **OWASP Top 10:** Protection against critical web application risks
- **CIS Benchmarks:** Following Center for Internet Security best practices
- **NIST Framework:** Aligned with NIST Cybersecurity Framework
- **ISO 27001:** Planned

#### Regular Audits

- **Security Audits:** Third-party penetration testing
- **Code Reviews:** Automated and manual security code reviews
- **Vulnerability Scanning:** Automated scanning for known vulnerabilities
- **Compliance Reviews:** Regular compliance assessments

### 4\. Access Controls

#### User Account Security

- **Strong Password Requirements:** Minimum 8 characters, complexity enforcement

#### Internal Access Controls

- **Principle of Least Privilege:** Employees have minimum necessary access
- **Role-Based Access Control (RBAC):** Access granted based on job function
- **Access Logging:** All internal access logged and auditable
- **Access Reviews:** Regular reviews of access permissions

### 5\. Security Monitoring

#### Automated Monitoring

- **Intrusion Detection:** Automated alerts for suspicious activity
- **DDoS Monitoring:** Automated monitoring for distributed attacks
- **Log Analysis:** System logs are collected and reviewed

### 6\. Incident Response

#### Incident Response Plan

We maintain a comprehensive incident response plan with defined procedures for:

- **Detection:** Rapid identification of security incidents
- **Containment:** Immediate isolation of affected systems
- **Eradication:** Removal of threats and vulnerabilities
- **Recovery:** Restoration of normal operations
- **Lessons Learned:** Post-incident analysis and improvements

#### User Notification

- **Breach Notification:** We notify affected users and regulators as required by applicable law, including notification to supervisory authorities within 72 hours where the GDPR requires it

### 7\. Data Protection

#### Data Backup & Recovery

- **Automated Backups:** Daily encrypted backups
- **Point-in-Time Recovery:** Restore data to recent points within our backup retention window
- **Disaster Recovery:** Documented disaster recovery plan

#### Data Minimization

- **Collect Only What's Needed:** Minimal data collection practices
- **Automatic Deletion:** Old data purged on schedule
- **User Control:** Delete your data at any time
- **Data Portability:** Export your data in machine-readable format

### 8\. Responsible Disclosure

We welcome security researchers to help keep MyOrbit secure, and we appreciate responsible disclosure of security vulnerabilities.

#### How to Report

If you discover a security vulnerability:

1. Email [security@myorbit.ai](mailto:security@myorbit.ai) with details
2. Include steps to reproduce the vulnerability
3. Allow us 90 days to address before public disclosure
4. Do not access user data or disrupt services

#### Safe Harbor

We will not pursue legal action against researchers who:

- Follow responsible disclosure guidelines
- Avoid privacy violations and service disruption
- Make good faith efforts to comply with our policies

### 9\. Best Practices for Users

#### Protect Your Account

- **Use Strong Passwords:** We enforce a minimum of 8 characters; we recommend 12 or more with a mix of letters, numbers, and symbols.
- **Beware of Phishing:** MyOrbit will never ask for your password via email
- **Keep Apps Updated:** Always use the latest version of MyOrbit apps

#### Privacy Settings

- **Set Your Content Level:** Choose your content level in Settings — Mature (18+) is opt-in and requires Confirmed Adult status.
- **Control Visibility:** Manage who can see your profile and AI twins
- **Review Permissions:** Regularly audit app permissions
- **Block Unwanted Users:** Use blocking and reporting features

#### Parental Controls

- **Link Accounts:** Parent and minor accounts can be linked using a one-time authorization code
- **General-Only Content:** Linked minor accounts are limited to General content
- **Screen Time Limits:** Set daily usage limits through your device's built-in screen-time controls

### 10\. Security Contact

#### Report a Security Issue

If you discover a security vulnerability or have security concerns:

- **Email:** [security@myorbit.ai](mailto:security@myorbit.ai)
- **Response Time:** We aim to acknowledge security reports promptly

#### General Security Questions

For non-urgent security questions or feedback:

- **Email:** [trust@myorbit.ai](mailto:trust@myorbit.ai)

#### Enterprise & Compliance

For enterprise security assessments and compliance inquiries:

- **Email:** [enterprise@myorbit.ai](mailto:enterprise@myorbit.ai)
- **Security Questionnaires:** We respond to vendor security assessments

**Questions?** Contact us at [security@myorbit.ai](mailto:security@myorbit.ai)

Related: [Privacy Policy](https://myorbit.ai/privacy) · [Terms of Service](https://myorbit.ai/terms) · [Safety Center](https://myorbit.ai/safety)
