Eorbitt — home
Book a technical call

Trust and security

This page exists to be forwarded to a security reviewer. Where a control is in place, the evidence that proves it is named. Where one is not, that is stated rather than implied.

Controls

Access

ControlHow it worksEvidence available
Least privilegeEngineers hold the narrowest access the work requires, requested per engagement and revoked at close.Access register, per client, with grant and revocation dates
Multi-factor authenticationEnforced on every Eorbitt account and on every client system that supports it.Tenant policy export
Privileged elevationAdministrative rights are time-bound and logged rather than standing.Elevation log covering the engagement period
Credential handlingClient credentials are held in a managed secret store, never in a repository, a ticket or a message.Secret store audit log

Controls

Data

ControlHow it worksEvidence available
Data locationClient data stays in the client's own accounts and regions wherever the architecture allows it.Architecture decision record naming the data location
Production data in developmentProduction data is not copied into development environments. Where realistic data is needed, it is generated or masked.Environment configuration and the masking script
Retention and deletionWhat Eorbitt holds, and for how long, is set per engagement and deleted on request within the contracted window.Deletion confirmation, issued in writing
SubprocessorsEvery third party with access to client data is listed before work starts, and changes are notified in advance.Subprocessor list, current version

Controls

Intellectual property

ControlHow it worksEvidence available
Ownership of work productCode, documentation and designs produced under an engagement are the client's on payment. Eorbitt retains no licence over them.Contract clause, provided before signature
Pre-existing componentsAnything Eorbitt brings with it is identified before use and licensed to the client perpetually and without fee.Component register in the handover pack
Open-source licensingDependency licences are checked in the pipeline, and copyleft licences are flagged before a dependency is adopted.Licence report from the build

Controls

People

ControlHow it worksEvidence available
ConfidentialityEvery person working on an engagement is bound by the same confidentiality terms Eorbitt agrees with the client, including contractors.Countersigned agreements, available on request
Background checksIdentity and right-to-work are verified before an engagement. Further screening is arranged where a client requires it.Verification record, subject to data protection law
Device standardsEngineering devices are encrypted, patched, and remotely wipeable, under managed configuration.Device compliance report

Controls

Incidents

ControlHow it worksEvidence available
NotificationA security incident affecting a client is reported to them within 24 hours of Eorbitt confirming it, before the cause is known.Contract clause and the incident log
ResponseContainment first, then evidence preservation, then a written cause analysis shared with the client.Incident record and the cause analysis
Business continuityRecovery objectives are set per system and restores are tested on a schedule, with failures reported as readily as passes.Restore test results, dated

Certifications

What Eorbitt does and does not hold

  • ISO/IEC 27001
    Eorbitt makes no ISO 27001 claim on this site until a certificate is in hand.
  • SOC 2 Type II
    No SOC 2 report is claimed. Clients requiring one should raise it during scoping.
  • Cloud partner status
    Partner tiers are listed only where a partner ID can be quoted.

Publishing an unearned badge is the fastest way to fail a security review, so these rows stay empty until the evidence exists. Where a client's process requires a certification Eorbitt does not hold, we will say so during scoping rather than at contract stage.

Incident response

What happens in the first ten days

Containment comes first. The affected access is revoked and the affected system is isolated before anything is investigated.

The client is told within 24 hours of Eorbitt confirming an incident, even when the cause is still unknown and the message is short.

Evidence is preserved before remediation, so a later investigation is not working from a cleaned-up system.

A written cause analysis follows within ten business days, covering what happened, what was affected, what was changed, and what will stop it recurring.

Where a regulator or a data subject must be notified, that is the client's decision to make, and Eorbitt provides what the notification requires.

Security questionnaires

Standard security questionnaires are answered directly rather than deflected to this page. Send yours with your first message and it comes back completed, with the gaps marked as gaps.

Book a technical callinfo@eorbitt.com