Our Commitment
Every report sent to security@orbitrasecurity.com is read by a person on the Orbitra engineering team. We route valid findings the same way we route production incidents: severity first, with a named owner and a fix date, not a queue position.
- We investigate on impact, not on how well the report was formatted.
- We keep the reporter updated until the issue is closed, including when we decide not to fix something.
- We credit researchers publicly when they want it, and stay quiet when they do not.
- We do not require a non-disclosure agreement as a condition of reporting.
This policy is also published in machine readable form, per RFC 9116, at /.well-known/security.txt.
Scope
The following assets are owned and operated by Orbitra Security and are in scope for testing under this policy:
- orbitrasecurity.com and orbitrasecurity.com, the public marketing site.
- app.orbitrasecurity.com, the Orbitra web application.
- api.orbitrasecurity.com and api-in.orbitrasecurity.com, the Orbitra product APIs.
Any other Orbitra system is out of scope by default. If you believe you have found something serious on an Orbitra asset that is not listed above, contact us before testing further and we will tell you whether we can authorize it.
Customer Microsoft Entra ID and Azure tenants are not ours to authorize. Do not test against a tenant you do not own, and do not use an Orbitra account, connection, or consent grant to reach one. Test only with accounts and data you control. If you need a test account in the Orbitra web application, ask us and we will provision one.
How to Report
Send your report to security@orbitrasecurity.com. Plain email is fine, and there is no form to fill in. Please send one issue per email.
Reports we can act on quickly usually include:
- The affected asset, URL, or API endpoint.
- A description of the issue and the impact you believe it has on a real customer environment.
- Reproduction steps, request and response pairs, or a short proof of concept.
- The account or role you tested from and the approximate time in UTC, so we can match your activity against our own logs.
- Whether you intend to publish, and on what timeline.
If the details are sensitive, say so in your first message without including them, and we will arrange an encrypted channel before you send anything further.
Safe Harbor
If you make a good faith effort to follow this policy, Orbitra will treat your research as authorized. We will not pursue or support legal action against you, and we will not refer you to law enforcement, for research that stays inside the rules below. If a third party brings action against you for work that followed this policy, we will make that authorization clear.
- Stay within the assets listed under Scope.
- Use only accounts and data you own or that we provided for testing.
- Stop as soon as you have proved the issue exists. Do not pivot further, escalate beyond what the proof requires, or access customer data.
- Do not degrade, disrupt, or deny service to other users.
- Do not modify, exfiltrate, or destroy data that is not yours.
- Give us reasonable time to remediate, and coordinate any publication with us.
This is an authorization for security research. It is not a waiver of our rights against activity that is not good faith research, including extortion, data theft, fraud, and attacks against customer tenants.
Response Targets
These targets apply to reports sent to security@orbitrasecurity.com and are measured in business days from when we receive the report.
- Acknowledgement, 2 business days. A person confirms we have your report and who owns it.
- Triage and severity, 5 business days. We tell you whether we reproduced the issue, the severity we assigned, and what we intend to do.
- Progress updates, every 10 business days while the issue remains open.
- Resolution, driven by severity. Findings that put customer tenants at risk are handled as incidents and take priority over planned work.
We will tell you when a fix ships. If we decide a finding will not be fixed, we will tell you that too, and why.
Out of Scope
The following are not accepted under this policy and are not covered by safe harbor:
- Denial of service, volumetric or stress testing, resource exhaustion, and automated scanning that degrades service for others.
- Social engineering, phishing, or pretexting against Orbitra staff, customers, contractors, or vendors.
- Physical attacks against offices, people, or hardware.
- Attacks against customer Entra ID or Azure tenants, or against Microsoft's own services. Platform issues belong to Microsoft.
- Findings in third party services we consume, unless you can demonstrate impact on an in-scope Orbitra asset.
- Raw scanner output, missing security headers, cookie flag preferences, TLS or email record opinions, and version disclosure, unless you can chain them into a demonstrated exploit.
- Issues that require an already compromised device, a malicious browser extension, or physical access to the victim's machine.
Recognition and Rewards
Orbitra does not run a paid bug bounty at this time, and there is no monetary reward for reports under this policy. We would rather state that plainly than imply otherwise.
What we do offer is public credit under your name or handle once a fix has shipped, if you want it, a written confirmation of the finding and its resolution that you are free to use in your own portfolio, and direct contact with the engineers fixing the issue. If we open a paid program, it will be announced on this page.
Contact
Vulnerability reports and any other security question, including questions about this policy, go to security@orbitrasecurity.com.
For privacy requests, see the Privacy Policy. For how Orbitra handles customer security data, see the Data use page. For general enquiries, use hello@orbitrasecurity.com.
Last updated: July 30, 2026