Security at Orbyt Labs

Last updated: September 2026

Your job search data is personal and sensitive. At Orbyt Labs, security is foundational to everything we build. This page describes the technical controls that protect your data.

Data Encryption

  • In transit: All connections use HTTPS, TLS 1.3 where the client supports it and TLS 1.2 otherwise. HSTS headers enforce HTTPS on every request. No fallback to unencrypted connections.
  • At rest: Database storage is encrypted using AES-256 via Supabase/AWS. Backups are encrypted with the same standard.
  • API keys (Unlimited plan): If you bring your own API keys on the Unlimited plan, your browser keeps a working copy and sends the keys to Orbyt over TLS, where they are encrypted with AES-256-GCM under a key derived for your account and stored in your account record so they follow you across devices. They are decrypted only for your authenticated session, they are stripped from the general settings sync, removing a key in Settings clears the stored copy, and deleting your account deletes it.

Authentication

  • Password policy: 12-character minimum, enforced server-side and scored with zxcvbn as you type. Passwords are hashed by Supabase Auth (bcrypt). Brute-force protection via progressive lockout, including a separate ceiling for password spraying across many accounts from one address.
  • Passkeys (WebAuthn): Phishing-resistant passwordless login using device biometrics or hardware security keys.
  • Two-factor authentication: TOTP-based 2FA support for accounts that want an additional layer beyond passwords.
  • Session management: Cookie-based sessions with HttpOnly flags and 7-day refresh tokens. Sessions are validated server-side on every protected request.

Access Controls

  • Row Level Security: Every database table enforces Supabase RLS policies. Your data is accessible only to your authenticated session. No other user and no admin can access your data without the service role key.
  • Per-user storage isolation: Uploaded files (profile images, contact photos) are scoped to per-user folders with storage-level access policies.
  • Service role key: The Supabase service role key is server-side only and never exposed to the browser. It is used exclusively for account deletion and webhook processing.

Infrastructure

  • Vercel: Edge network hosting with automatic TLS termination, DDoS protection, and auto-scaling. No self-managed servers.
  • Supabase: Managed PostgreSQL on AWS infrastructure with encrypted storage, automated backups, and built-in auth.
  • Stripe: PCI DSS Level 1 compliant payment processing. Card data is collected and processed entirely by Stripe. Payment details never touch our servers.
  • Rate limiting: All API endpoints are rate-limited via Upstash Redis (with in-memory fallback) to prevent abuse.

AI Privacy

Free, Pro, and Ultra plans include hosted AI powered by Orbyt's server-side keys, with no API key setup needed. The Unlimited plan uses a Bring Your Own Key (BYOK) model for power users who want zero caps and full data privacy.

  • Hosted AI (Free, Pro, Ultra): AI prompts are processed through Orbyt's server-side API keys. We do not log, store, or inspect prompt content. Prompts are processed in real time and are not used to train AI models.
  • BYOK keys are encrypted at rest (Unlimited): On the Unlimited plan, your API keys for OpenAI, Anthropic, and xAI are encrypted server-side with AES-256-GCM under a per-account derived key and stored in your account record, which is how they sync across your devices. Each AI request passes through our server-side proxy, which forwards your key to the provider you chose for that request, so the key is never sent to a provider from your browser.
  • No training on your data: Orbyt never uses your job search data or AI interactions for model training. Your data stays yours.
  • Voice recordings: When you use voice capture, audio is recorded in your browser and sent to OpenAI's Whisper API through Orbyt's edge proxy. On Free, Pro, and Ultra, voice data is processed through Orbyt's hosted OpenAI key. On Unlimited, it flows through your own API key. Audio is never stored on our servers. Only the resulting transcription text is used.

Application Security

  • Content Security Policy: A CSP restricts which origins may load scripts, frames, and connections, and frame-ancestors blocks clickjacking. It is not a nonce-based policy today, so it narrows script injection rather than eliminating it.
  • Security headers: HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy are enforced on all responses.
  • Origin verification: All API routes verify the request origin to prevent CSRF attacks.
  • Input sanitization: All user input is validated and sanitized. No dynamic code execution or raw HTML injection anywhere in the codebase.
  • Webhook authentication: Supabase and Stripe webhooks are verified via HMAC signatures using constant-time comparison.
  • Microphone permission: Voice features use the browser's native Permissions API. Microphone access is requested only on user action (clicking the mic button) and can be revoked at any time. Orbyt never accesses the microphone in the background.

Monitoring

  • Sentry: Production error monitoring with privacy-safe defaults. All text is masked and all media is blocked in session replays. Error reports contain stack traces and device metadata only.
  • Audit logging: 42 audited event types covering authentication (login, signup, passkey registration, MFA enrollment and removal, session revocation), billing actions (subscription create, cancel, reactivate, plan change, refund, disputes), team administration, and data operations (export, account deletion). Audit entries are stored in a service-role-only table with no client access, purged automatically by a daily database job on a 90-day retention window, and deleted outright when the account they belong to is deleted.
  • Pre-commit sentinel: Every code change passes through an automated security scan covering missing auth checks, missing origin verification, 11 hardcoded-secret patterns, 5 dangerous DOM and dynamic-code patterns, and logging that could leak sensitive values.

Uptime & Status

We monitor Orbyt's availability around the clock. View real-time and historical uptime data on our public status page.

Compliance

  • GDPR data export: Export all your data as JSON at any time from Settings. Full data portability with one click.
  • Right to deletion: Delete your account from Settings. Cascade deletes remove all database records, uploaded files, and stored credentials.
  • No advertising cookies: Orbyt uses cookies for authentication (Supabase session cookies) and, inside the signed-in app, for first-party product analytics (PostHog). No advertising cookies, no ad-tech pixels, and no third-party trackers. The full list is in our Privacy Policy.
  • Data processing details: Our Data Processing Agreement and Privacy Policy cover sub-processors, retention, and breach notification. Both describe current practice: there is no executed DPA or signed SCCs on file for self-serve accounts. Organizations that need one can contact privacy@orbytlabs.ai.

Responsible Disclosure

If you discover a security vulnerability, please report it responsibly to security@orbytlabs.ai. We take all reports seriously and will acknowledge receipt within 48 hours. We will not take legal action against researchers who follow responsible disclosure practices.

← Back to Orbyt Labs