Security Policy
Last updated July 31, 2026
In short. We take security seriously: passwords are hashed, traffic is encrypted, sensitive data is protected at rest, and we offer two-factor authentication. No online service can promise perfect security, so we also tell you how to protect yourself and how to report a vulnerability responsibly.
This Security Policy describes the measures OrbitSub, operated by KARAN (“we”), takes to protect your data, and the part you play too. It supports our obligations under the Digital Personal Data Protection Act, 2023. Security researchers should also see our Responsible Disclosure Policy.
1. How we protect your data
- Passwords are hashed. We store passwords using bcrypt, a strong one-way hashing algorithm. We can never see your actual password.
- Encryption in transit. Traffic between you and the Service is encrypted using TLS (HTTPS).
- Sensitive data encrypted at rest. Particularly sensitive data, such as two-factor authentication secrets, is encrypted at rest using strong symmetric encryption (AES-256-GCM).
- Secure sessions. We use short-lived access tokens together with rotating refresh tokens that are stored only in hashed form, so a stored token cannot be reused if exposed. The session cookie is HttpOnly and, in production, sent only over HTTPS.
- Two-factor authentication. You can enable 2FA in Settings for an extra layer of protection, which we strongly recommend.
- Abuse and bot protection. We use bot-protection checks, rate limiting, and access controls to defend against automated attacks and unauthorised access.
- Least-exposure design. Payment details are handled by PayPal and not stored by us, so the most sensitive financial data never sits on our systems.
- Startup safety checks. In production, the Service refuses to start unless critical security configuration (such as encryption keys) is properly set, so it cannot run in an insecure state.
2. Your part in staying secure
Security is a shared responsibility. You can help protect your account by:
- choosing a strong, unique password you don’t reuse elsewhere;
- enabling two-factor authentication;
- keeping your password and devices private, and signing out on shared devices;
- being alert to phishing — we will never ask for your password by email;
- telling us promptly at team@orbitsub.com if you notice anything suspicious about your account.
3. No system is perfectly secure
We work hard to protect your data, but no method of transmission or storage over the internet is completely secure, and we cannot guarantee absolute security. We provide the Service’s security measures on a commercially reasonable, best-effort basis.
4. If a breach happens
If we become aware of a personal-data breach that is likely to affect you, we will act to contain it and will notify you and the Data Protection Board of India as required by the DPDP Act, including what happened and what you can do to protect yourself.
5. Reporting a vulnerability
If you are a security researcher or notice a potential vulnerability, please report it responsibly under our Responsible Disclosure Policy rather than disclosing it publicly or exploiting it. We appreciate good-faith help keeping OrbitSub safe.
6. Changes and contact
We may update this Policy as our security practices evolve; the current version and the “Last updated” date are shown here. For any security question, contact us at team@orbitsub.com.