How we protect your data and your customers' data. Last updated: July 2026
Orbidex is a multi-tenant IT Help Desk and Asset Management platform. Each customer's data is isolated, access-controlled, and encrypted. We are built on enterprise-grade cloud infrastructure and follow industry best practices for web application security.
| Provider | Purpose | Data Stored | Region |
|---|---|---|---|
| Supabase | Database & Authentication | All application data, user credentials | US East (AWS) |
| Render | Application Hosting | Application code, logs (30 days) | US Oregon (AWS) |
| Resend | Transactional Email | Email addresses, notification content | US |
| Category | Practice | Status |
|---|---|---|
| Data isolation | Each company's data is scoped by company_id; cross-tenant access is impossible at the application layer |
Enforced |
| Data in transit | TLS 1.2+ enforced; all API calls and database connections encrypted | Enforced |
| Data at rest | AES-256 encryption via Supabase (managed) | Enforced |
| Attachment retention | Configurable per company (default 6 months); automatic cleanup | Configurable |
| Audit logging | All admin actions logged with actor, timestamp, before/after values | Enabled |
| Right to deletion | Full customer data deletion available on account termination | Available |
We take security reports seriously. If you discover a vulnerability, please report it to our security contact below before public disclosure. We aim to acknowledge reports within 48 hours and resolve confirmed issues within 30 days.