OrbitZR
Security & Trust

Your work belongs to you. We protect it.

Your projects, tasks, conversations, files, and client information matter. OrbitZR is built to protect your organization's data while giving you control, visibility, and the ability to take your data with you.

Security  •  Privacy  •  Transparency  •  Data Control

Your organization OrbitZR Protected workspace

Projects

Tasks

Files

Team members

Client data

Access-controlled
Scoped to your organization & workspace members only

Security isn't a promise. It's a process.

We believe organizations should be able to understand how their data is handled rather than simply being asked to trust a vendor. OrbitZR's security program is built around protecting customer data, limiting access, maintaining reliable infrastructure, and giving customers control over their information.

Protect

Protect customer information using appropriate technical and organizational safeguards.

Control

Control who can access projects, workspaces, and organizational information.

Audit

Maintain visibility into important account and administrative activity.

Export

Keep your data portable with workspace export capabilities.

ownership

Your data belongs to you.

OrbitZR does not acquire ownership of your organization's content. Your projects, boards, cards, comments, files, documents, and other customer content remain yours.

OrbitZR receives only the rights necessary to provide, secure, maintain, and improve the OrbitZR service as described in our agreements and policies.

Read our Privacy Policy

Customer data

Projects
Boards
Cards
Comments
Files
Attachments
Team information
Activity
Client information

data stewardship

Your data works for you, and only you.

Your organization's data is not a product. It's used for one purpose: to provide, secure, and improve the OrbitZR service your team relies on. Nothing else.

Yours Alone

Your project and organizational data stays yours: it's never sold or brokered to third parties.

Built for Your Team

Your project activity stays focused on running your team's work, not on building ad or marketing profiles.

Purpose-Limited Processing

Customer information is processed to provide and operate OrbitZR, according to applicable agreements and policies.

For complete details about how information is collected, processed, retained, and disclosed, please refer to the OrbitZR Privacy Policy and applicable customer agreements.

AI & automation

Your data doesn't automatically become AI training data.

OrbitZR's AI features are designed to work with your organization's information to provide the functionality you request, like generating a checklist or answering a question inside your workspace. Customer data is not used to train general-purpose AI models without explicit authorization.

Enterprise customers can discuss AI data processing requirements directly with the OrbitZR security team.

Your workspace OrbitZR AI Requested task Result for your organization

AI data controls

AI features
Use customer data for requested AI features
Use customer data for general model training Disabled by default

technical safeguards

Protection at every step.

OrbitZR uses industry-standard security practices to protect information while it moves between users, services, and storage systems.

Encryption in Transit

Data transmitted between your browser, mobile app, APIs, and OrbitZR infrastructure is protected using modern TLS encryption (HTTPS).

Encryption at Rest

Stored customer information is protected using encryption provided by our underlying infrastructure and storage providers.

Browser / Mobile HTTPS / TLS → OrbitZR Application → Encrypted Storage → Encrypted Backups

multi-tenant architecture

Your workspace stays yours.

OrbitZR is designed with logical separation between organizations and workspaces, so users can only access information they're authorized to access.

Company A

Workspace A

  • ├── Projects
  • ├── Boards
  • └── Cards
Isolated

Company B

Workspace B

  • ├── Projects
  • ├── Boards
  • └── Cards

Authorization at every request

Workspace-level access control

Role-based permissions

Tenant-aware data access

access control

The right people. The right access.

Access to organizational information is based on a user's role and the workspaces they've been added to.

Role-Based Access

Admin and Participant roles control what different users can view and manage.

Workspace Permissions

Projects and organizational data stay limited to invited, authorized members.

Authentication

Secure, hashed-credential authentication protects every account.

Session Security

Web sessions and per-device mobile tokens are independent: signing out one device never touches the others.

Planned

Multi-factor authentication (MFA) and single sign-on (SSO) are on our roadmap. See the compliance roadmap below.

accountability

Know what happened.

Security and accountability require visibility. Every board and card already keeps an activity trail of key changes. A dedicated, filterable audit log across your whole organization is on our roadmap for Enterprise customers.

Enterprise · Coming Soon

Audit activity

AD

Admin user

Updated workspace permissions

Today · 10:42 AM

S

Sarah

Added a member to Project Alpha

Today · 09:31 AM

M

Michael

Exported a Tasklist report

Yesterday · 04:12 PM

AD

Admin

Changed board security settings

Yesterday · 02:18 PM

freedom through portability

Your data shouldn't hold you hostage.

Moving to OrbitZR should never mean losing control of your information. We believe customers should have practical ways to export their data, and we're building toward that goal in stages.

Your workspace
CSV XLSX / PDF
Downloadable report

Available today

  • Tasklist reports as CSV, XLSX, DOCX, or PDF
  • Live board sync to Google Sheets (Power-Up)

Planned: full workspace export

Boards
Cards
Lists
Comments
Labels
Checklists
Members
Attachments
Activity
Workspace info
Learn about data export

migration

Coming Soon

Switching from Trello? Bring your work with you.

You shouldn't have to rebuild your organization from scratch. We're building a migration workflow that imports supported Trello data and lets you review the migration before committing to it.

Trello export Upload / Connect Migration engine Compatibility check Preview Approve OrbitZR workspace
Preview mockup

Migration preview (illustrative)

Boards24
Lists137
Cards4,382
Comments11,294
Attachments2,781
Warnings3

Some third-party Power-Ups, custom automations, integrations, or proprietary Trello functionality may require manual configuration after migration.

migration

Coming Soon

Moving from Jira? Keep your project history.

We're developing migration capabilities for teams moving from Jira, focused on preserving useful project information while clearly identifying anything that needs mapping or manual configuration.

Projects Issues Users Comments Attachments Statuses Labels Sprints OrbitZR

Migration compatibility report (illustrative)

Target: 92% ready to migrate

Projects
Issues
Comments
Attachments
Custom fields
Marketplace apps
Custom workflows
Request a Migration Assessment

continuous improvement

Security is continuously tested.

Our security program includes ongoing vulnerability management, security reviews, dependency monitoring, and infrastructure monitoring as the platform grows, with independent testing planned as part of our compliance roadmap.

Vulnerability Management

Identify, prioritize, and remediate security vulnerabilities.

Dependency Security

Monitor third-party libraries and dependencies for known issues.

Security Testing

Application and infrastructure security assessments.

Independent Testing

Qualified third parties for penetration testing and security reviews, planned as part of our roadmap.

infrastructure

Built on trusted infrastructure.

OrbitZR runs on managed cloud infrastructure with dedicated layers for the application, database, and file storage.

Users Secure HTTPS OrbitZR API
Application Storage
Database Files
Backups

Cloud infrastructure

Managed cloud hosting

Database

Relational database with automated backups

Object storage

Managed file & attachment storage

Monitoring

Application & infrastructure monitoring

resilience

Your work should be recoverable.

Reliable backups and disaster recovery processes help protect customer information from infrastructure failures, accidental deletion, and unexpected incidents.

Backups

Automated backups of critical systems and data.

Recovery

Documented recovery procedures for critical systems.

Business Continuity

Processes designed to maintain and restore service during major incidents.

We haven't published fixed RPO/RTO targets yet. Formal, tested numbers are part of our compliance roadmap below rather than a claim we'd make without independent verification.

documentation

Privacy and compliance, clearly documented.

Privacy Policy

What information OrbitZR collects and how it's processed.

Read Privacy Policy

Terms of Service

The relationship between OrbitZR and its customers.

Read Terms

Data Processing Agreement

A DPA for customers who require formal data-processing terms.

Request DPA

Security Documentation

Enterprise customers can request additional security information.

Contact Security

roadmap

Building toward enterprise-grade assurance.

OrbitZR is not currently SOC 2 certified. As we grow, our security program will continue to mature through independent assessments, documented controls, and formal compliance programs.

Current

Security Foundation

Planned

Independent Security Assessment

Planned

SOC 2 Readiness

Planned

SOC 2 Type I

Planned

SOC 2 Type II

internal controls

Customer data access is controlled.

Our policy is that access to production systems is limited to authorized personnel who need it for legitimate operational or security purposes.

Request Access Approval Limited Access Activity Logged Access Revoked

Least privilege

Role-based access

Production access controls

Activity monitoring

Access review

incident response

If something happens, we respond.

Security incidents require a defined process. OrbitZR maintains procedures for identifying, investigating, containing, resolving, and communicating security incidents.

Detect

Investigate

Contain

Resolve

Communicate

Security contact security@orbitzr.com

at a glance

Enterprise security checklist.

A transparent snapshot of what's built today, and what's still on the way.

Data ownership Done
Encryption in transit Done
Authentication Done
Authorization (RBAC) Done
Tenant isolation Done
AI data controls Done
Data portability In Progress
Auditability In Progress
Backups In Progress
Incident response process In Progress
Privacy documentation Planned
Data Processing Agreement Planned
Independent security assessments Planned
Multi-factor authentication Planned

Have security requirements?

Tell us what your organization requires. Our team can discuss security controls, data processing, architecture, migration, compliance requirements, and enterprise deployment options.

Request Enterprise Review

Security panel

Tenant isolation
Role-based access
TLS encryption in transit
SOC 2 Type II Planned

questions

Security & trust FAQ.

Does OrbitZR sell customer data?

No. Customer data is not sold as a data product. OrbitZR processes customer information to provide the service and according to applicable agreements and policies.

Who owns the data stored in OrbitZR?

Customers retain ownership of their organization's content and data, subject to the terms of the applicable agreement.

Can we export our data?

Yes, today Tasklist reports export as CSV, XLSX, DOCX, or PDF, and boards can live-sync to Google Sheets. A broader, workspace-wide export (boards, cards, comments, checklists, attachments, and activity) is on our roadmap. See Data Portability above.

Can we migrate from Trello?

A Trello migration workflow with a compatibility review step is in development. See Migration above. It isn't available yet. Some third-party Power-Ups and unsupported features will likely require manual migration once it launches.

Can we migrate from Jira?

We're developing Jira migration capabilities. Compatibility will depend on your Jira configuration, custom fields, workflows, and marketplace applications. It isn't available yet.

Does OrbitZR use our data to train AI?

No. Customer data is not used to train general-purpose AI models without explicit authorization. AI processing is limited to the functionality enabled for your workspace.

Is OrbitZR SOC 2 certified?

Not yet. OrbitZR is not currently SOC 2 certified. See our compliance roadmap above for where we are today and what's planned next.

Can OrbitZR employees access our data?

Production access is restricted to authorized personnel who need it for legitimate operational or security purposes, following least-privilege and role-based access principles. See Employee Access above.

What happens if we leave OrbitZR?

You should be able to get your supported workspace data out. OrbitZR does not intend to use vendor lock-in as a retention mechanism. Data portability is a roadmap priority, not an afterthought.

Security questions?

If your organization has security, privacy, compliance, or migration requirements, contact the OrbitZR team.

Work confidently with OrbitZR.

Secure your projects. Control your data. Give your team the freedom to work.