Security
Last updated: April 2025
At Orbital ERP, the security of your business data is our highest priority. We have implemented multiple layers of protection to ensure your data remains confidential, available, and tamper-proof.
1. Data Encryption
- In Transit: All data transmitted between your browser/device and our servers is encrypted using TLS 1.2 or higher (HTTPS). We enforce HSTS to prevent downgrade attacks.
- At Rest: Sensitive data stored in our databases is encrypted at rest using AES-256 encryption.
- Passwords: User passwords are never stored in plaintext. They are hashed using industry-standard algorithms (bcrypt) with salting.
2. Payment Security
Orbital ERP uses Razorpay for all payment processing. Razorpay is a PCI-DSS Level 1 certified payment gateway — the highest level of certification in the payments industry. We do not store, process, or transmit full card numbers (PANs), CVV codes, or other sensitive cardholder data on our servers. All such data is handled exclusively by Razorpay's secure infrastructure.
We retain only transaction IDs, masked card identifiers (last 4 digits), and payment status records for billing and reconciliation purposes.
3. Access Control
- Role-Based Access Control (RBAC): Users within an organization are assigned roles with the minimum permissions necessary for their function.
- Organisation Isolation: Each organisation's data is logically isolated. No user can access data belonging to another organisation.
- Multi-Factor Authentication (MFA): MFA support is available for enhanced account security.
- Session Management: User sessions expire after a period of inactivity. All active sessions can be reviewed and revoked from account settings.
4. Infrastructure Security
- Our platform is hosted on secure, ISO 27001-certified cloud infrastructure.
- Servers are protected by firewalls, with only necessary ports exposed to the internet.
- Regular automated security patching is applied to all operating systems and dependencies.
- Intrusion detection and alerting systems monitor for anomalous activity.
- Automated daily backups with point-in-time recovery capability.
5. Application Security
- Our codebase follows OWASP Top 10 guidelines to mitigate common web vulnerabilities including SQL injection, XSS, and CSRF.
- All API endpoints are authenticated and rate-limited.
- Input validation is enforced on both client and server sides.
- Third-party dependencies are regularly audited and updated.
6. Employee Access
Access to customer data by Orbital ERP employees is restricted to personnel who need it to provide support or operate the Service. All such access is logged and audited. Employees are bound by confidentiality obligations.
7. Incident Response
In the event of a security incident affecting your data, we will notify affected customers via email within 72 hours of confirming the breach, in accordance with applicable data protection obligations. Notifications will include the nature of the incident, data affected, and steps we are taking to address it.
8. Compliance
- PCI-DSS: Payment processing via Razorpay (PCI-DSS Level 1 certified).
- India IT Act 2000 & DPDP Act 2023: We comply with applicable Indian data protection and information technology laws.
- GST Compliance: All billing and invoicing is GST-compliant.
9. Responsible Disclosure
We take security reports seriously. If you discover a security vulnerability in our platform, please report it responsibly to:
- Email: admin@orbitalerp.in
Please do not publicly disclose the vulnerability until we have had a reasonable opportunity to investigate and address it. We will acknowledge your report within 48 hours and keep you updated on our progress.
10. Contact
For security-related questions or concerns:
- Email: admin@orbitalerp.in
- Phone: +91 7778878433
- Address: 9, Devshrut Villa, Opposite Samarth Heaven 5, Ahmedabad, Gujarat 382426, India