How ScanOrbit protects your account and your data, written for the person filling in a vendor security review. If you need something that isn't here, email hello@scanorbit.app and we'll answer directly or complete your questionnaire.
1. Where your data lives
ScanOrbit's database, sign-in, file storage and backend run on Supabase, hosted on Amazon Web Services in N. Virginia, United States (us-east-1). The website and the redirects behind every QR code run on Vercel's network. All customer data is stored in the United States.
The providers that handle data, and what each receives, are listed on our Subprocessors page.
2. Encryption
All traffic to ScanOrbit, the dashboard, the API and QR redirects, is served over HTTPS (TLS). Data at rest is encrypted by our database provider.
Passwords are hashed by our sign-in provider and never stored in readable form. API keys are stored only as a SHA-256 fingerprint: we can't see or recover a key after it's created.
3. Signing in
Email and password, or Google sign-in.
Two-factor authentication with any authenticator app is available to every account, and is enforced by the server, not just the screen: a session that hasn't entered the code can't reach any data. Account owners on the Business plan can require two-factor authentication for everyone on their team.
You can end every session at once from Settings → Security → Sign out everywhere, and a session that has been ended elsewhere is signed out as soon as it's next used.
4. Team access control
Each person gets their own login; nobody shares a password. Roles are Owner (everything, including billing), Admin (everything except billing, the scan domain and roles), Member (create and manage QR codes) and Viewer (sees everything, changes nothing). Roles are enforced by the server on every request.
Everything created in a team belongs to the account, so removing someone takes away their access without taking their work.
5. Audit log
Every change to an account is recorded: who made it (the person, or which API key), what changed and when. That covers QR codes, folders, cards, contacts, settings, domains, API keys, webhook secrets, passwords, team invites, joins, role changes and removals, billing, and data exports.
When ScanOrbit support changes something on your account, it's recorded in your log too. Owners and admins on the Business plan can view, search and export the log.
6. API and webhooks
API keys can be full access or read only, can expire after 30 days, 90 days or a year, and can be revoked instantly. Each key is limited to 120 requests a minute, and requests without a valid key share a stricter limit.
Webhooks are signed with HMAC-SHA256 using a secret you can rotate at any time, so your server can verify each request came from ScanOrbit.
7. Privacy of people who scan your codes
We record device type, operating system, browser and approximate location (country and city) for each scan. Location comes from our hosting provider's network as part of handling the request; visitor IP addresses aren't sent to any separate location service, and aren't stored in readable form. A one-way hash is kept only to count unique scans.
Scan pages don't carry advertising or tracking scripts of ours. Retargeting pixels only appear if the account owner adds them.
8. Your data, your control
Account owners can download everything in their account as one file, and delete their account themselves, at any time from Settings → Security → Your data. Deletion is immediate; invoices and payment records are kept because tax and accounting law requires it.
9. What we don't have yet
ScanOrbit doesn't hold SOC 2 or ISO 27001 certification, and doesn't offer SAML single sign-on (SSO) or SCIM user provisioning today. If any of these is a hard requirement for your organization, we'd rather you know now.
We're happy to complete your security questionnaire, and we offer a Data Processing Agreement (see our DPA page).
10. Reporting a vulnerability
If you find a security problem, please email hello@scanorbit.app with the details and how to reproduce it. Please don't access other people's data or disrupt the service while testing. We'll acknowledge your report and keep you updated as we fix it.
Questions regarding Security?
hello@scanorbit.app