SHEET S-01 · TRUST & SECURITY
Security at Orbiseed
Orbiseed processes construction bid documents and product data for enterprise customers. Protecting that information is a core operating requirement. This page describes how we communicate about security, how to reach our security team, and how to report a vulnerability.
Security notifications
We notify affected customers of confirmed security incidents and of material changes to our security posture by email to each customer's designated security contacts, as required by our Incident Response and Communications Policy (Policy 325, Section 4.0). Customers can add or update their designated security contacts at any time by writing to ciso@orbiseed.com.
Security contact
ciso@orbiseed.com is the address for all security matters, including security questionnaires, compliance documentation requests, and incident communications. It is the security contact of record in our Information Security Policy (Policy 315, Appendix A).
Reporting a vulnerability
If you believe you have found a security vulnerability in an Orbiseed product, service, or website, email ciso@orbiseed.com with a description of the issue, the steps to reproduce it, and any relevant URLs, requests, or samples. We acknowledge vulnerability reports within two business days.
We will not pursue or support legal action against good-faith security research that avoids privacy violations, data destruction, and service degradation, and that allows us reasonable time to remediate before any public disclosure.
A machine-readable contact record is published at security.txt.
Compliance
Orbiseed maintains a formal information security program with documented policies covering access control, incident response, vendor management, and customer communications. A SOC 2 Type II program is underway. Current security documentation is available to customers and prospects under NDA through ciso@orbiseed.com.