Governance

Information Security Policy

Effective October 15, 2026

Orbit AI Technologies Corporation (“Orbit AI”) is committed to protecting the systems and information entrusted to us, including the information users provide when Orbit carries out tasks on their behalf.

Scope

This policy applies to Orbit AI’s systems, services, and data, and to the people and service providers who access them.

Our approach

We take a risk-based approach to security: we identify the information and systems that matter most, apply safeguards proportionate to the risk, and review those safeguards as Orbit and the threat landscape change.

Access control

  • Access to systems and data is limited to people and services that need it, following the principle of least privilege.
  • Access is authenticated, reviewed, and removed when it is no longer needed.
  • Orbit is designed to act only within the permissions a user grants and to require approval for sensitive actions.

Data protection

  • We use technical and organizational measures designed to protect information in transit and at rest.
  • Sensitive information, such as credentials and payment details, is handled with additional care and is not exposed beyond what a task requires.
  • We aim to keep information only as long as it is needed. See our Privacy Policy for details.

Secure development and operations

Security is considered throughout design, development, and operation, including isolated environments for task execution, change management, and monitoring of our systems.

Vulnerability reporting

If you believe you have found a security vulnerability in Orbit or this website, please contact Orbit AI with a description of the issue and steps to reproduce it. Please act in good faith: do not access, modify, or delete data that is not yours, do not disrupt our services, and give us reasonable time to address the issue before disclosing it. We appreciate responsible reports and will review them promptly.

Incident response

We maintain a process for identifying, containing, investigating, and recovering from security incidents. Where an incident affects users, we will notify them as required by applicable law.

Vendor management

We evaluate service providers that handle Orbit AI data or support our services, expect them to maintain appropriate security practices, and limit their access to what they need.

Personnel responsibilities

Everyone with access to Orbit AI systems is expected to follow our security practices and to report suspected security issues promptly.

Changes to this policy

We may update this policy as Orbit, our practices, and applicable requirements evolve. The effective date above shows when it was last revised.

Contact

For security questions or to report a concern, please contact Orbit AI.