Security
Orbyts holds payroll and employment records. This page describes the controls that protect them.
Data residency
The platform runs in Amazon Web Services' Asia Pacific (Sydney) region. Employee personal information is stored and processed in Australia.
Encryption
- Traffic to the platform is served over HTTPS with HSTS enforced.
- Databases and backups are encrypted at rest.
- Outbound email is delivered over TLS, and we refuse to deliver it in the clear.
Access and authentication
- Multi-factor authentication, which an organisation can require of all of its users.
- Single sign-on through Microsoft Entra ID for organisations that use it.
- Role-based permissions, so people see the records their role allows and no more.
- Each customer's data is separated from every other customer's.
Account safety
- A sign-in from a device we have not seen before triggers an email to the account holder, showing the device, time, approximate location and IP address.
- That email carries a one-click action to revoke the session if the sign-in was not theirs.
- Security notices of this kind cannot be switched off by an administrator.
- Password reset links are single-use and expire within an hour.
Auditability
Changes to employment and remuneration records are recorded with who made them and when, so a figure in a pay run can be traced back to the decision behind it.
Reporting a vulnerability
If you believe you have found a security issue, please tell us at hello@orbytsgroup.com. We will acknowledge your report, keep you updated while we investigate, and will not pursue action against researchers who report in good faith and avoid privacy violations or service disruption.