Trust and security
This page exists to be forwarded to a security reviewer. Where a control is in place, the evidence that proves it is named. Where one is not, that is stated rather than implied.
Controls
Access
| Control | How it works | Evidence available |
|---|---|---|
| Least privilege | Engineers hold the narrowest access the work requires, requested per engagement and revoked at close. | Access register, per client, with grant and revocation dates |
| Multi-factor authentication | Enforced on every Eorbitt account and on every client system that supports it. | Tenant policy export |
| Privileged elevation | Administrative rights are time-bound and logged rather than standing. | Elevation log covering the engagement period |
| Credential handling | Client credentials are held in a managed secret store, never in a repository, a ticket or a message. | Secret store audit log |
Controls
Data
| Control | How it works | Evidence available |
|---|---|---|
| Data location | Client data stays in the client's own accounts and regions wherever the architecture allows it. | Architecture decision record naming the data location |
| Production data in development | Production data is not copied into development environments. Where realistic data is needed, it is generated or masked. | Environment configuration and the masking script |
| Retention and deletion | What Eorbitt holds, and for how long, is set per engagement and deleted on request within the contracted window. | Deletion confirmation, issued in writing |
| Subprocessors | Every third party with access to client data is listed before work starts, and changes are notified in advance. | Subprocessor list, current version |
Controls
Intellectual property
| Control | How it works | Evidence available |
|---|---|---|
| Ownership of work product | Code, documentation and designs produced under an engagement are the client's on payment. Eorbitt retains no licence over them. | Contract clause, provided before signature |
| Pre-existing components | Anything Eorbitt brings with it is identified before use and licensed to the client perpetually and without fee. | Component register in the handover pack |
| Open-source licensing | Dependency licences are checked in the pipeline, and copyleft licences are flagged before a dependency is adopted. | Licence report from the build |
Controls
People
| Control | How it works | Evidence available |
|---|---|---|
| Confidentiality | Every person working on an engagement is bound by the same confidentiality terms Eorbitt agrees with the client, including contractors. | Countersigned agreements, available on request |
| Background checks | Identity and right-to-work are verified before an engagement. Further screening is arranged where a client requires it. | Verification record, subject to data protection law |
| Device standards | Engineering devices are encrypted, patched, and remotely wipeable, under managed configuration. | Device compliance report |
Controls
Incidents
| Control | How it works | Evidence available |
|---|---|---|
| Notification | A security incident affecting a client is reported to them within 24 hours of Eorbitt confirming it, before the cause is known. | Contract clause and the incident log |
| Response | Containment first, then evidence preservation, then a written cause analysis shared with the client. | Incident record and the cause analysis |
| Business continuity | Recovery objectives are set per system and restores are tested on a schedule, with failures reported as readily as passes. | Restore test results, dated |
Certifications
What Eorbitt does and does not hold
- ISO/IEC 27001Eorbitt makes no ISO 27001 claim on this site until a certificate is in hand.
- SOC 2 Type IINo SOC 2 report is claimed. Clients requiring one should raise it during scoping.
- Cloud partner statusPartner tiers are listed only where a partner ID can be quoted.
Publishing an unearned badge is the fastest way to fail a security review, so these rows stay empty until the evidence exists. Where a client's process requires a certification Eorbitt does not hold, we will say so during scoping rather than at contract stage.
Incident response
What happens in the first ten days
Containment comes first. The affected access is revoked and the affected system is isolated before anything is investigated.
The client is told within 24 hours of Eorbitt confirming an incident, even when the cause is still unknown and the message is short.
Evidence is preserved before remediation, so a later investigation is not working from a cleaned-up system.
A written cause analysis follows within ten business days, covering what happened, what was affected, what was changed, and what will stop it recurring.
Where a regulator or a data subject must be notified, that is the client's decision to make, and Eorbitt provides what the notification requires.
Security questionnaires
Standard security questionnaires are answered directly rather than deflected to this page. Send yours with your first message and it comes back completed, with the gaps marked as gaps.