Security

Your accounts, handled with care

Orbin connects to the platforms your audience lives on. We treat that access, and your data, as a responsibility.

Practices

How we protect your data

Encrypted access tokens

Social OAuth tokens are encrypted at rest and decrypted only when needed to publish or sync on your behalf.

Workspace isolation

Every workspace’s data is scoped and access-controlled, so one account can never read another’s content or connections.

Least-privilege OAuth

We request only the permissions a feature needs, and you can revoke a connection from your account at any time.

Protected connection flow

Account connections use signed, single-use CSRF state and rate limiting to defend against forged or replayed requests.

Account safeguards

Passwords are hashed, sessions are protected, and admin-only actions gate who can connect or remove accounts.

Trusted payments

Billing is handled by Stripe. We never see or store your full card details.

Responsible disclosure

Found a vulnerability?

We appreciate the security community. If you believe you’ve found a security issue in Orbin, please email us at support@orbin.io with details and steps to reproduce. Please give us a reasonable window to investigate and fix before any public disclosure, and avoid accessing or modifying data that isn’t yours.

Orbin is operated by ValidPixel, LLC. For how we handle personal data, see our Privacy Policy.