Your code is yours. We built Orbit to keep it that way.
Your code lives on your machine, not our servers
We minimize data collection, not maximize it
We tell you exactly what data goes where
You decide what's shared, synced, or kept local
Orbit is a desktop app — your projects live on your computer, not in the cloud. Code is NOT uploaded to Orbit servers by default. You control what gets synced or shared. Even AI features process locally when possible.
AI agents need to see code to help — here's how that works transparently:
When you use AI features
Code context is sent to AI providers (OpenAI, Anthropic) to generate responses. These providers have their own privacy policies — we use API access that doesn't train on your data.
Bring your own keys
Use your own API keys for full control over your AI provider relationship.
Local models
Support for local and self-hosted models is on our roadmap for maximum privacy.
All network traffic uses TLS 1.3
Sensitive data encrypted at rest
Secure auth with industry-standard protocols
Strict internal access policies
Hosted on SOC 2 compliant infrastructure
We're a young company building toward enterprise-grade compliance. SOC 2 certification is actively in progress.
For companies evaluating Orbit:
SAML/OIDC support
Deploy Orbit on your infrastructure
Track activity across your organization
Choose where data is stored
We complete your security questionnaire
Contact us for enterprise security discussions.
We welcome responsible disclosure of security vulnerabilities.
Contact us with any security questions.
We're happy to discuss security with your team. Enterprise customers get dedicated security support.
Security-first development environment. Your code stays yours.
From local-first architecture to transparent AI, security isn't an afterthought — it's foundational.