Legal
Security posture
This page describes orbitGRC’s approach to security. It does not confer regulatory or audit certification.
Approach
orbitGRC is designed for AMCs and other regulated financial organizations. The platform is built to support defense-in-depth practices, including audit logging, evidence integrity, role-based access control, multi-factor authentication for privileged users, and customer-controlled cloud deployment options.
Data handling
orbitGRC is designed for in-India data residency by default. Specific data residency, region and tenancy details vary by customer deployment and are confirmed as part of the commercial engagement.
Access controls
Access to orbitGRC is governed by role-based access control following a least-privilege model. Sensitive workflows are protected by maker-checker discipline, so that the submitter of a change cannot also be its approver.
Audit logging
Workflows in orbitGRC are audit-logged so that controls, evidence, approvals and assessments can be reconstructed for review. Final audit assurance is always provided by the customer’s internal or external auditors, not by the platform itself.
Incident response
orbitGRC maintains documented incident-response runbooks. Customer notification in the event of an incident follows the terms agreed in the customer’s contract.
Third parties
orbitGRC uses a limited set of sub-processors. The current list of sub-processors is maintained per the DPDP notice and customer agreement, and is available on request.
Note
This page describes our approach to security. It does not confer regulatory or audit certification. Final security assurance for any specific deployment is established by customer-specific configurations and contractual terms.
Reach out
For security questions, deployment-specific posture detail, or to request our current sub-processor list, get in touch via the contact page. You can also review our privacy notice and DPDP notice.