FACTUAL SECURITY & PRIVACY ARCHITECTURE

Security Built for Multi-Tenant Agency Operations

When you manage multiple client brands in a single system, tenant isolation is not a marketing checkbox. It is an architectural commitment. Here is exactly how Orbit Cue protects your data.

PostgreSQL Row-Level Security (RLS)•AES-256-GCM Token Encryption•European Union Hosting (Frankfurt)

Strict Tenant & Brand Isolation

Database queries are constrained by PostgreSQL Row-Level Security (RLS). Posts, media assets, schedule queues, and audit logs are strictly scoped to the active workspace organization and brand context.

AES-256-GCM Credential Vault

Social OAuth access tokens, client secrets, and refresh tokens are encrypted at rest using AES-256-GCM authenticated encryption with unique initialization vectors (IVs) and authentication tags before persistence.

Role-Based Access (RBAC)

Workspace access is governed by explicit roles: owner, admin, member, and reviewer. Team members only access the client brands they are explicitly assigned to.

Signed Media Access

Draft post imagery and creative media reside in private storage buckets. Public access is strictly prohibited; downloads utilize time-limited signed URLs generated on-demand.

EU Managed Infrastructure

Orbit Cue utilizes Supabase enterprise infrastructure (hosted in Frankfurt, Germany - AWS eu-central-1) and Vercel edge networks, fully adhering to European General Data Protection Regulation (GDPR) mandates.

Paddle Merchant of Record

Payment card details never touch Orbit Cue servers. Transactions, PCI compliance, and global sales tax / EU reverse charge calculations are handled securely by Paddle.com.

Responsible Vulnerability Disclosure

We value the security research community. If you identify a potential security vulnerability in Orbit Cue, please report it immediately to our engineering team at hello@orbitcue.app. We investigate all legitimate reports promptly and coordinate responsible disclosures without legal retribution.