Perth · Western AustraliaTrust centrehello@orbitwren.com
OrbitWren
Trust centre

Our controls are maintained through automated evidence collection wired into delivery pipelines — the same approach we implement for clients. Everything below can be substantiated on request.

AccessLeast privilegeDataResidency agreedDocumentsOn request
Security operations screen in a darkened room
Certifications

Nothing on this list is aspirational. Where a framework applies to how we work rather than a certificate we hold, it says so.

Least-privilege accessScoped, time-bound credentials on client systems; no shared logins
Encryption in transit and at restTLS everywhere, managed keys, no secrets in source control
Dependency and secret scanningAutomated checks in CI, with findings triaged before release
Data processing agreementsSigned per engagement, with residency agreed in writing
Audit trailsInfrastructure and data access logged and reviewable on request
Tested restoresBackups verified by restore drills, not assumed
Security posture

01

Access control

Identity-based access with short-lived credentials, hardware-backed MFA for all staff, and no standing production access. Elevation is time-boxed and logged.

02

Data handling

Client data stays in the client's environment wherever the work allows. Where it cannot, it is encrypted at rest and in transit, region-pinned, and covered by a signed processing agreement.

03

Secure development

Dependency scanning, static analysis and secret detection run on every merge. Findings above an agreed severity block the build rather than opening a ticket.

04

Incident response

A documented, rehearsed process with defined notification timelines. Game days are run quarterly against injected failures, not tabletop scenarios.

05

Business continuity

Recovery objectives are tested rather than assumed. Restore drills happen on a schedule and the results are shared with clients on request.

06

Personnel

Background checks appropriate to jurisdiction, security training on joining and annually, and access revocation completed within the hour on departure.

Stack

The technologies behind the work published on this site. We hold no vendor partner tier and do not claim one — and we stay willing to recommend against any of these when it is the wrong tool.

AWSCertified Cloud Practitioner
PythonFastAPI · Celery · LangChain
TypeScriptNode · NestJS · Express
ReactNext.js · Vite · React Native
PostgreSQLPrisma · SQLAlchemy · pgvector
DockerContainerised build and deploy
FirebaseAuth and message delivery
MediaPipeOn-device inference
Documentation

Write to hello@orbitwren.com and we will send these under NDA, usually within two working days.

  • Security practices summary
  • Subprocessor list and data flow diagrams
  • Standard data processing agreement
  • Business continuity and disaster recovery plan
  • Insurance certificates (professional indemnity, cyber)

Send us the questionnaire. We complete security reviews as a matter of routine and would rather do it early than at contract stage.