1. Overview
OrbitExSpace Inc. ("OrbitExSpace", "we", "us") takes the security of our digital systems and the protection of our users' data seriously. This page describes our security practices and our coordinated vulnerability disclosure process.
Security is an ongoing practice. We continuously work to identify, evaluate, and mitigate risks to our systems and the information we process. We engage with the broader security community in good faith and welcome responsible reporting of potential vulnerabilities.
2. Security Practices
We apply a range of technical and organizational safeguards, including:
- Encrypted data transmission using Transport Layer Security (TLS) for all connections to the Site.
- Infrastructure operated by reputable cloud providers with rigorous physical and environmental security controls.
- Access controls limiting data and systems to authorized personnel on a least-privilege basis.
- Regular security reviews and remediation of identified issues.
- Logging and monitoring to detect and respond to anomalous activity.
- Data minimization — we collect and retain only what is necessary to operate the Site and respond to inquiries.
3. Coordinated Vulnerability Disclosure
We welcome reports of potential security vulnerabilities affecting the Site. If you believe you have identified a security issue, we ask that you report it to us responsibly and allow us a reasonable opportunity to investigate and remediate before any public disclosure.
To encourage responsible reporting, we commit to the following:
4. Reporting Guidelines
When reporting a vulnerability, please:
- Provide a clear description of the issue, including steps to reproduce it.
- Avoid accessing, modifying, or destroying data that does not belong to you.
- Refrain from degrading or disrupting the availability of the Site or our systems.
- Do not attempt to exploit the vulnerability beyond what is necessary to demonstrate it.
- Allow us a reasonable time to investigate and remediate before any public disclosure.
We will not pursue legal action against good-faith reporters who follow these guidelines. We may acknowledge responsible reporters at their discretion.
Please send vulnerability reports to security@orbitexspace.com with a detailed description. We aim to acknowledge receipt within a reasonable timeframe.
5. Scope
This disclosure process applies to vulnerabilities affecting the OrbitExSpace website and our directly operated digital infrastructure. It does not apply to third-party services we use, which should be reported to their respective security teams.
The following are out of scope: denial-of-service attacks, volumetric attacks, social engineering, physical attacks, and any activity that could harm users or disrupt service.
6. Incident Response
In the event of a confirmed security incident affecting personal data, we will investigate and take appropriate steps to contain and remediate the incident. Where required by law, we will notify affected individuals and the relevant authorities without undue delay.
7. Contact
For security-related questions or to report a vulnerability, please contact us:
OrbitExSpace Inc.
Los Angeles, California
security@orbitexspace.com
Legal & Compliance Contact — legal@orbitexspace.com
This document is provided for informational purposes only and does not constitute legal advice or a representation of certification, accreditation, registration, Government approval, contract status, or authorization. OrbitExSpace programs are in development. Statements regarding FAR/DFARS, ITAR, EAR, NIST SP 800-171, CMMC, or other frameworks apply only where applicable and as required by contract or law.
OrbitExSpace Inc.