OrbitalReg Sign in →

Trust & security

Built for procurement reviews.

OrbitalReg is engineered for the kind of due-diligence that kills competitor deals. Every claim on this page links to evidence — a config flag, a doc, a roadmap item — so your security team can verify rather than take our word for it.

01 — Compliance posture

Where we stand on the audits your security team will ask about.

No vapourware. Status reflects today, not aspirations. Items in progress have a target window and a public roadmap reference.

SOC 2 Type II

Pre-audit phase

Evidence engine shipped — every controllable assertion in Trust Services Criteria has a corresponding artifact in the product. Auditor selection in progress. Trust Service Criteria targeted: Security, Availability, Confidentiality.

Pre-audit evidence pack available under NDA — request via info@orbitalreg.com.

ISO 27001

Controls mapped

Annex A controls mapped to product features and operational practice. Mapping documented in docs-site/compliance/iso27001/ — every control points to the OrbitalReg artifact that satisfies it.

Certification is on the medium-term roadmap; mapping is the prerequisite. Mapping document available under NDA.

GDPR

Compliant by design

EU-only data residency. Data Processing Agreement (/legal/dpa) ready to counter-sign at contract time. Privacy policy at /datenschutz. Right-to-erasure and data-export procedures documented.

Single sub-processor: IONOS Cloud (Frankfurt) for hosting + SMTP. Listed in DPA appendix.

Supply-chain integrity

SLSA-aligned

Every release artifact carries Sigstore signatures, an SBOM, and build-info provenance (CI run, commit SHA, builder identity). Customers can verify before deploy without trusting us.

Verification recipes in migration docs and the customer portal.

02 — Security architecture

Defence in depth — without a separate security licence.

OrbitalReg's security features are part of the product, not an upcharge tier. The list below is what every install gets, day one.

Encryption

TLS 1.3 for all in-transit traffic. At-rest encryption is operator-controlled — OrbitalReg ships with documented recipes for LUKS-encrypted artifact volumes and Postgres volume encryption, including KMS-backed key management.

Authentication

SAML 2.0 / OIDC for the OrbitalReg core admin (Azure Entra, Okta, Keycloak — verified). Token-based auth for the artifact API with scoped grants. Magic-link auth for the customer portal — no passwords stored. Every action attributable to a principal.

Air-gap mode

First-class operational mode — flips egress to deny-all in one config line. Vendored CVE feeds, signed update bundles delivered out-of-band, no build-time assumption of internet access.

Audit log

Structured JSON, SIEM-ready out of the box (Loki, Splunk, Elastic recipes shipped). Every admin action, token issuance, and policy change carries actor, timestamp, and request ID for forensic reconstruction.

Verify-on-pull gates

Cryptographic signature verification before any artifact leaves the registry — CMS, OpenPGP, RSA, Sigstore. Pulls of unverified artifacts are blocked at the gate. Per-repo policy.

CVE detection

Trivy and Grype scan every artifact at upload and on demand. Results stay on customer hardware — no upstream phone-home. Auto-quarantine policy available for newly-discovered CVEs on artifacts already in the registry.

03 — Supply-chain posture

Verifiable from upstream to deploy.

SolarWinds-grade questions about "how do we know the binary you shipped is the binary you built?" — answered with cryptography, not assertions.

Supply-chain case studies

Retrospective analyses of major incidents. Each one names the specific OrbitalReg feature that would have caught it — and the caveats where the defence stops short.

Cargo · Aug 2026

Rust crates backdoor →

Malware in cargo build via a poisoned build script. Patch-version quarantine + pull-gate.

npm · live — Aug 2026

The keyv npm worm →

Self-propagating credential worm with IDE hooks. Curated proxy + quarantine + pull-gate.

NuGet · May 2026

Sicoob.Sdk banking-credential theft →

Fake bank SDK stole mTLS certs via Sentry; the GitHub repo stayed clean. Curation + provenance scrutiny.

AI era · 2023 — ongoing

Slopsquatting & package hallucinations →

LLMs invent package names; attackers register them. Curated proxies + pull-gate + audit signal.

npm · Sept & Nov 2025

Shai-Hulud worm →

Self-replicating npm worm. CVE-gate + pull-block + air-gap promotion.

xz-utils · March 2024

CVE-2024-3094 backdoor →

Source vs tarball divergence. Build-info provenance + reproducible-build gate.

Birsan / PyTorch · 2021–2022

Dependency confusion →

Public names outranking private feeds. Internal-first virtual repos + namespace audit.

log4j · December 2021

Log4Shell — CVE-2021-44228 →

Cross-repo CVE search + pull-gate on critical + SBOM transitive index.

node-ipc · March 2022

When the maintainer is the attacker →

Pull-gate + patch-version quarantine + behavioural diff (roadmap).

SolarWinds · December 2020

SUNBURST & verifiable vendor builds →

How we built OrbitalReg to make a SolarWinds-class compromise of us externally verifiable.

CodeCov · April 2021

curl | bash and SHA-pinning →

Mirror vendor scripts as content-addressable artifacts; promote on diff review.

04 — Data protection & residency

Your data, in your jurisdiction.

OrbitalReg's product runs on your infrastructure — your hardware, your jurisdiction, your control. The OrbitalReg-operated services listed below are limited to what's strictly required to deliver licences and support.

Hosting jurisdiction

All OrbitalReg-operated services (customer portal, software distribution, magic-link mail) run in IONOS Frankfurt. EU-only, no third-country transfers, GDPR-aligned by infrastructure choice.

Sub-processors

Single sub-processor: IONOS Cloud (Frankfurt) for hosting + SMTP. No US-cloud, no third-country routing. Full list in the DPA appendix.

Data minimisation

Customer-portal data limited to: email, optional display name, optional company, login timestamps, license-request use-case text. No artifact content, no usage telemetry, no metering.

Retention

Customer-portal records deleted within 30 days of contract termination on written request. Audit logs retained 12 months for security forensics, then purged.

05 — Documents & contacts

Signing-ready, on request.

Document

Data Processing Agreement

GDPR Art. 28 DPA, ready to counter-sign. Sub-processor list, TOMs, breach-notification SLA.

Document

Privacy policy

Datenschutzerklärung. What we collect, why, how long, and your rights as a data subject.

Document

EULA

End-User License Agreement covering installed-software terms, warranties, and termination.

Procurement support

Need a security questionnaire filled, an architecture diagram, a custom DPA clause, or a pre-audit evidence pack?

Email info@orbitalreg.com with subject line Procurement review support — typical turnaround under 48 hours.