1. Accounts and security
Each person uses an individual account. Credentials must not be shared. Users protect passwords, passkeys, recovery keys and tokens and promptly revoke compromised access.
2. Tenants and permissions
Owners and administrators manage invitations, roles and workspace access. Users may access only content for which they are authorised and must not bypass technical controls.
3. Permitted use
OrbitOne must not be used for unlawful content, malware, phishing, spam, unauthorised surveillance or access, attacks, infringement of third-party rights, circumvention of security or loads that materially impair normal operation.
4. Content and files
Users may process only content for which they have the required rights. Personal, confidential and sensitive data must be handled according to its sensitivity. Shared links and exports must be distributed carefully.
5. Vault
Vault entries may contain highly sensitive information. Access should be restrictive and recovery information stored safely. OrbitOne cannot always restore lost end-to-end keys or exclusively client-encrypted content.
6. Repositories and APIs
Repository credentials, webhooks and API tokens must be protected, limited to required scopes and revoked when unused. Integrations may be used only within the permissions and terms of all involved systems.
7. Guests
Guests receive only expressly granted workspace access. Inviting organisations review identity, scope and duration. Guests follow the same security and content rules as members.
8. Protective action
Tokens, content, functions or accounts may be temporarily restricted for concrete security risks, serious abuse, legal violations or payment default. Where reasonable, notice and an opportunity to remedy are provided. Report incidents to support@orbitone.io.