Your projects, tasks, conversations, files, and client information matter. OrbitZR is built to protect your organization's data while giving you control, visibility, and the ability to take your data with you.
Security • Privacy • Transparency • Data Control
Projects
Tasks
Files
Team members
Client data
We believe organizations should be able to understand how their data is handled rather than simply being asked to trust a vendor. OrbitZR's security program is built around protecting customer data, limiting access, maintaining reliable infrastructure, and giving customers control over their information.
Protect customer information using appropriate technical and organizational safeguards.
Control who can access projects, workspaces, and organizational information.
Maintain visibility into important account and administrative activity.
Keep your data portable with workspace export capabilities.
ownership
OrbitZR does not acquire ownership of your organization's content. Your projects, boards, cards, comments, files, documents, and other customer content remain yours.
OrbitZR receives only the rights necessary to provide, secure, maintain, and improve the OrbitZR service as described in our agreements and policies.
Customer data
data stewardship
Your organization's data is not a product. It's used for one purpose: to provide, secure, and improve the OrbitZR service your team relies on. Nothing else.
Your project and organizational data stays yours: it's never sold or brokered to third parties.
Your project activity stays focused on running your team's work, not on building ad or marketing profiles.
Customer information is processed to provide and operate OrbitZR, according to applicable agreements and policies.
For complete details about how information is collected, processed, retained, and disclosed, please refer to the OrbitZR Privacy Policy and applicable customer agreements.
AI & automation
OrbitZR's AI features are designed to work with your organization's information to provide the functionality you request, like generating a checklist or answering a question inside your workspace. Customer data is not used to train general-purpose AI models without explicit authorization.
Enterprise customers can discuss AI data processing requirements directly with the OrbitZR security team.
AI data controls
technical safeguards
OrbitZR uses industry-standard security practices to protect information while it moves between users, services, and storage systems.
Data transmitted between your browser, mobile app, APIs, and OrbitZR infrastructure is protected using modern TLS encryption (HTTPS).
Stored customer information is protected using encryption provided by our underlying infrastructure and storage providers.
multi-tenant architecture
OrbitZR is designed with logical separation between organizations and workspaces, so users can only access information they're authorized to access.
Company A
Workspace A
Company B
Workspace B
Authorization at every request
Workspace-level access control
Role-based permissions
Tenant-aware data access
access control
Access to organizational information is based on a user's role and the workspaces they've been added to.
Admin and Participant roles control what different users can view and manage.
Projects and organizational data stay limited to invited, authorized members.
Secure, hashed-credential authentication protects every account.
Web sessions and per-device mobile tokens are independent: signing out one device never touches the others.
Multi-factor authentication (MFA) and single sign-on (SSO) are on our roadmap. See the compliance roadmap below.
accountability
Security and accountability require visibility. Every board and card already keeps an activity trail of key changes. A dedicated, filterable audit log across your whole organization is on our roadmap for Enterprise customers.
Enterprise · Coming SoonAudit activity
Admin user
Updated workspace permissions
Today · 10:42 AM
Sarah
Added a member to Project Alpha
Today · 09:31 AM
Michael
Exported a Tasklist report
Yesterday · 04:12 PM
Admin
Changed board security settings
Yesterday · 02:18 PM
freedom through portability
Moving to OrbitZR should never mean losing control of your information. We believe customers should have practical ways to export their data, and we're building toward that goal in stages.
Available today
Planned: full workspace export
migration
Coming SoonYou shouldn't have to rebuild your organization from scratch. We're building a migration workflow that imports supported Trello data and lets you review the migration before committing to it.
Migration preview (illustrative)
Some third-party Power-Ups, custom automations, integrations, or proprietary Trello functionality may require manual configuration after migration.
migration
Coming SoonWe're developing migration capabilities for teams moving from Jira, focused on preserving useful project information while clearly identifying anything that needs mapping or manual configuration.
Migration compatibility report (illustrative)
Target: 92% ready to migrate
continuous improvement
Our security program includes ongoing vulnerability management, security reviews, dependency monitoring, and infrastructure monitoring as the platform grows, with independent testing planned as part of our compliance roadmap.
Identify, prioritize, and remediate security vulnerabilities.
Monitor third-party libraries and dependencies for known issues.
Application and infrastructure security assessments.
Qualified third parties for penetration testing and security reviews, planned as part of our roadmap.
infrastructure
OrbitZR runs on managed cloud infrastructure with dedicated layers for the application, database, and file storage.
Cloud infrastructure
Managed cloud hosting
Database
Relational database with automated backups
Object storage
Managed file & attachment storage
Monitoring
Application & infrastructure monitoring
resilience
Reliable backups and disaster recovery processes help protect customer information from infrastructure failures, accidental deletion, and unexpected incidents.
Automated backups of critical systems and data.
Documented recovery procedures for critical systems.
Processes designed to maintain and restore service during major incidents.
We haven't published fixed RPO/RTO targets yet. Formal, tested numbers are part of our compliance roadmap below rather than a claim we'd make without independent verification.
documentation
Enterprise customers can request additional security information.
Contact Securityroadmap
OrbitZR is not currently SOC 2 certified. As we grow, our security program will continue to mature through independent assessments, documented controls, and formal compliance programs.
Security Foundation
Independent Security Assessment
SOC 2 Readiness
SOC 2 Type I
SOC 2 Type II
internal controls
Our policy is that access to production systems is limited to authorized personnel who need it for legitimate operational or security purposes.
Least privilege
Role-based access
Production access controls
Activity monitoring
Access review
incident response
Security incidents require a defined process. OrbitZR maintains procedures for identifying, investigating, containing, resolving, and communicating security incidents.
Detect
Investigate
Contain
Resolve
Communicate
at a glance
A transparent snapshot of what's built today, and what's still on the way.
Tell us what your organization requires. Our team can discuss security controls, data processing, architecture, migration, compliance requirements, and enterprise deployment options.
Request Enterprise ReviewSecurity panel
questions
No. Customer data is not sold as a data product. OrbitZR processes customer information to provide the service and according to applicable agreements and policies.
Customers retain ownership of their organization's content and data, subject to the terms of the applicable agreement.
Yes, today Tasklist reports export as CSV, XLSX, DOCX, or PDF, and boards can live-sync to Google Sheets. A broader, workspace-wide export (boards, cards, comments, checklists, attachments, and activity) is on our roadmap. See Data Portability above.
A Trello migration workflow with a compatibility review step is in development. See Migration above. It isn't available yet. Some third-party Power-Ups and unsupported features will likely require manual migration once it launches.
We're developing Jira migration capabilities. Compatibility will depend on your Jira configuration, custom fields, workflows, and marketplace applications. It isn't available yet.
No. Customer data is not used to train general-purpose AI models without explicit authorization. AI processing is limited to the functionality enabled for your workspace.
Not yet. OrbitZR is not currently SOC 2 certified. See our compliance roadmap above for where we are today and what's planned next.
Production access is restricted to authorized personnel who need it for legitimate operational or security purposes, following least-privilege and role-based access principles. See Employee Access above.
You should be able to get your supported workspace data out. OrbitZR does not intend to use vendor lock-in as a retention mechanism. Data portability is a roadmap priority, not an afterthought.
If your organization has security, privacy, compliance, or migration requirements, contact the OrbitZR team.
Secure your projects. Control your data. Give your team the freedom to work.