ORBITEXSPACE
L21Cybersecurity

Cybersecurity Policy

1. Overview

OrbitExSpace Inc. ("OrbitExSpace", "we", "us") designs and operates systems whose integrity matters. This page describes our cybersecurity commitments across our current website and information systems and our future spacecraft and mission systems. It supplements our Website Security Policy and Coordinated Vulnerability Disclosure process.

This policy is provided for informational purposes and does not disclose security architecture, vulnerabilities, credentials, internal controls, or sensitive operational procedures. Statements regarding specific frameworks apply where applicable and as required by contract or law.

2. Cybersecurity Frameworks and Standards

For covered systems, information, personnel, and activities, we align our cybersecurity program with recognized frameworks, as applicable and as required by contract or law, including:

  • NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, and successor versions, for covered systems handling CUI/CDI.
  • NIST SP 800-53 and the NIST Cybersecurity Framework ('CSF'), as applicable to the sensitivity and mission of the system.
  • CMMC model requirements, where a contract requires CMMC certification, and only after verification of any certification status we represent.
  • Applicable aerospace-cybersecurity guidance for spacecraft and mission systems as our programs mature.

We do not represent that we are CMMC certified or that any particular system is assessed or authorized unless and until that status is verified. Where DFARS clause 252.204-7012 and NIST SP 800-171 apply by contract, we implement and maintain the required security controls for covered defense information.

3. Spacecraft Cybersecurity

Future spacecraft will be designed with cybersecurity as a first-class concern. This includes authenticated and integrity-protected command and telemetry links, segmentation of critical and non-critical functions, secure boot and software integrity, and the ability to recover from anomalous or hostile interference. We will apply applicable aerospace-cybersecurity guidance as our programs mature.

4. Mission Systems Security

Mission systems — the ground and on-orbit systems used to plan, command, and monitor a mission — will be protected against unauthorized access, tampering, and denial of service. Access is granted on a least-privilege basis, actions are logged, and sensitive functions require multi-factor authentication.

5. Ground Systems Security

Ground systems, including ground stations and mission control, will be hardened against attack and monitored for intrusion. We segment ground systems from general-purpose networks, apply encryption to control links, and maintain incident-response capability.

6. Data Security and CUI/FCI Handling

We protect data — personal data, technical data, and mission data — with controls appropriate to its sensitivity: encryption in transit and at rest, access controls, logging, and secure deletion when data is no longer needed. Where we handle CUI or FCI under a covered contract, we apply the identification, marking, safeguarding, and transmission controls required by the applicable contract and NIST SP 800-171. We do not retain sensitive data longer than necessary.

7. Telemetry and Mission Data

Telemetry and mission data — including planning data, command history, and results — are protected against tampering and unauthorized disclosure. Access is limited to authorized personnel, derived data products are handled according to their classification, and data is retained only as long as needed for mission analysis and regulatory compliance.

8. Remote Sensing and Geospatial Data

Any geospatial data we collect or process is handled in accordance with applicable law and any conditions imposed by the source. If we ever operate a remote-sensing or Earth-observation capability, we will obtain the required NOAA license or equivalent national authorization before operation and will comply with applicable conditions, including restrictions on resolution, distribution, and shutter control. We do not currently operate any remote-sensing system.

9. Website and Current Systems

The security of our current website is described in our Website Security Policy, which also describes our coordinated vulnerability disclosure process. Reports of security vulnerabilities affecting our internet-facing systems should be sent to security@orbitexspace.com per that policy.

10. Contact

For cybersecurity policy or compliance inquiries, contact:

OrbitExSpace Inc.
Legal & Compliance
legal@orbitexspace.com

Legal & Compliance Contact — legal@orbitexspace.com

This document is provided for informational purposes only and does not constitute legal advice or a representation of certification, accreditation, registration, Government approval, contract status, or authorization. OrbitExSpace programs are in development. Statements regarding FAR/DFARS, ITAR, EAR, NIST SP 800-171, CMMC, or other frameworks apply only where applicable and as required by contract or law.

COOKIES

This site uses essential cookies to function and optional analytics to understand how it is used. We do not sell data. See our Cookie Policy for details.