Security and privacy

Security is built into every layer of Orbit.

Orbit follows modern security best practices and recognized industry standards to help protect business data, member records, and financial workflows while keeping the platform reliable and trustworthy.

Security focus Protect. Monitor. Recover.

Security is an ongoing process across infrastructure, access control, development, backups, and support.

1

Secure infrastructure

Orbit is built for businesses that handle sensitive financial and member information. The platform is designed to run on secure, professionally managed server infrastructure with regular updates, controlled access, and operational checks that support availability and resilience.

  • We use HTTPS/TLS on production deployments to secure traffic between users and the platform.
  • We restrict server access to authorized technical personnel only.
  • We monitor hosting, domain, and SSL settings so login, white-label domains, and mobile app links remain reliable.
2

How customer data is protected

Orbit is designed to keep each company's records separated, so members, staff, wallets, savings, loans, investments, commodity credits, messages, and reports remain tied to the correct company account.

  • Security controls are designed around common industry guidelines for privacy, access control, logging, and secure operations.
  • Company data is handled inside controlled company workspaces.
  • Sensitive settings such as API keys and passwords are not displayed back in plain text after saving.
  • Public pages only show information the company has chosen to publish.
3

Login, roles, and permissions

Companies can assign staff roles and permissions so users only access the areas needed for their work. This follows the principle of least privilege: each user only sees and performs what their role requires. Member portal access is separate from company staff access.

  • We provide password-protected access, and authorized users keep login details private as part of their account responsibility.
  • Payment PIN controls can protect sensitive member transfer actions where enabled.
  • Companies can remove staff access immediately when a staff member leaves.
4

Secure development

Security is considered throughout the development and maintenance process. Updates are reviewed carefully, sensitive workflows are tested before release, and issues are addressed promptly when discovered.

  • Financial actions such as wallet movement, approvals, auto-debits, and provider callbacks are treated as high-risk workflows.
  • Important changes are tested locally before being prepared for live update.
  • We apply security updates and bug fixes quickly when a vulnerability or operational risk is identified.
5

Monitoring, audit trails, and reliability

Orbit keeps audit-friendly records for important actions such as wallet movement, approvals, savings, loans, repayments, bill payments, commodity activity, notifications, settings changes, and login/security events where available.

  • Transaction history helps companies reconcile balances and investigate mistakes.
  • Email logs, scheduler runs, and notification records help track what the system attempted to send or process.
  • We provide logs and reports so unusual provider responses, failed callbacks, or wrong postings can be reviewed quickly.
6

Backups and recovery

We take backups very seriously. Orbit production environments run continuous daily backup routines for database records and important uploaded files, helping protect business continuity if accidental loss, hosting failure, or server migration occurs.

Companies can also download their own backup from the Data Backup area whenever they want. This gives each company an additional physical or onsite copy of its records for internal control, audit, and business continuity.

  • Companies can download their data backup as often as their internal policy requires.
  • We monitor platform backups and test recovery periodically, not only create backup files.
  • We include uploaded files, logos, app icons, and website images in backup planning.
  • Companies can avoid accidental data loss by confirming important records before deleting them.
7

Privacy and responsible data handling

We are committed to protecting customer data by following recognized security and privacy best practices. Orbit is designed to support confidentiality, integrity, and responsible handling of member and company information.

  • Companies control the public information shown on their website and white-label pages.
  • We treat payment gateway credentials, API keys, and provider settings as confidential.
  • Companies are responsible for obtaining proper consent before enabling auto-debits, messaging, or sensitive member workflows.
8

Our commitment

Security is an ongoing process, not a one-time feature. We continually review and improve Orbit's controls to align with evolving industry practices, customer needs, and emerging operational risks.

  • We help companies review domains, SSL, staff permissions, and backup expectations before go-live.
  • We encourage regular review of approval settings, notification settings, and payment controls.
  • If something looks wrong, companies can contact support quickly with screenshots, dates, references, affected members, and the page where the issue happened.
Need assurance?

Talk to NewKipp before onboarding sensitive data.

We can help review your domain, SSL, permissions, backup expectations, and go-live checklist.