Trust & Security
Last updated 8 August 2026
Your data does not come to us
OrbitSOC is designed so that we are not in the path.
The platform runs in your infrastructure or your cloud tenant — AWS, Google Cloud, Azure, or your own hardware. Inference runs through the model provider you choose, in your tenant, under your agreement with that provider. We work with all major providers; we do not impose one, and there is no default that routes your telemetry anywhere by design.
The practical consequence is worth stating plainly: in a standard deployment there is no OrbitSOC-controlled AI subprocessor. Your security telemetry does not reach a model vendor of our choosing, because we do not choose one. For regulated environments, that removes the question that usually stalls an AI security procurement for a month.
The division of labour
OrbitSOC investigates. You decide.
The platform produces classified verdicts, supporting evidence, timelines and containment recommendations. Declaring an incident, approving containment and deploying detection content remain human decisions. Nothing that touches one of your systems executes without explicit human approval, and a single control freezes every agent.
This is an architectural choice, not a setting. It can conclude. It cannot declare.
How data is handled
| Control | What we actually do |
|---|---|
| Cardholder data | Detection rules identify PCI data and redact it before it enters the investigation pipeline. |
| Retention | Configured by you. Because the platform runs in your environment, retention of investigation content is under your control and set to your policy — not ours. |
| Model provider | Chosen by you and run in your tenant. Any no-training commitment is the one in your own agreement with that provider, which we would encourage you to read. |
| Prompt injection | Log and alert content is treated as data, never as instruction. Untrusted content is isolated from the instruction path. |
| Evidence validation | Conclusions are checked against the underlying evidence rather than accepted as generated. |
Reporting a vulnerability
Email security@orbitsoc.com. We will acknowledge within two business days and keep you updated through to resolution.
We will not pursue legal action against good-faith security research that respects customer data, avoids degrading service for others, stays within systems you are authorised to test, and gives us reasonable time to remediate before public disclosure.
Subprocessor changes
We give 30 days' notice before adding or replacing a subprocessor that processes customer data. Customers may object under their Data Processing Addendum. Write to legal@orbitsoc.com to be added to the notification list.