Your accounts, handled with care
Orbin connects to the platforms your audience lives on. We treat that access, and your data, as a responsibility.
How we protect your data
Encrypted access tokens
Social OAuth tokens are encrypted at rest and decrypted only when needed to publish or sync on your behalf.
Workspace isolation
Every workspace’s data is scoped and access-controlled, so one account can never read another’s content or connections.
Least-privilege OAuth
We request only the permissions a feature needs, and you can revoke a connection from your account at any time.
Protected connection flow
Account connections use signed, single-use CSRF state and rate limiting to defend against forged or replayed requests.
Account safeguards
Passwords are hashed, sessions are protected, and admin-only actions gate who can connect or remove accounts.
Trusted payments
Billing is handled by Stripe. We never see or store your full card details.
Found a vulnerability?
We appreciate the security community. If you believe you’ve found a security issue in Orbin, please email us at support@orbin.io with details and steps to reproduce. Please give us a reasonable window to investigate and fix before any public disclosure, and avoid accessing or modifying data that isn’t yours.
Orbin is operated by ValidPixel, LLC. For how we handle personal data, see our Privacy Policy.