Trust
Trust & Security
A concise summary of how we protect the OrionAlerts website and product surfaces visitors interact with today.
Effective 8 September 2026 · Last reviewed 2026-09-08
Security program summary
OrionAlerts is building enterprise video and operations software. For the public website and current lead intake path, we apply the following baseline controls:
- HTTPS for production traffic once TLS is correctly configured on the canonical host.
- HttpOnly, SameSite=Lax admin session cookie (oa_admin_session) with a 12-hour lifetime after successful login.
- Server-side rate limiting on lead submissions and Google reCAPTCHA on the demo form.
- Separation of demo and contact lead kinds in application handling (durable CRM/ERP storage not yet connected).
- Least-privilege access to admin publishing tools via password-gated sessions.
Customer product deployments (on-prem or cloud) are governed by the customer’s architecture review and the commercial agreement, not solely by this website page.
Responsible disclosure
If you believe you have found a security vulnerability in the OrionAlerts website or a product surface you are authorized to test, email security@orionalerts.com with steps to reproduce, impact assessment, and your contact details. Please do not access or modify other customers’ data, or disrupt production services.
We do not currently operate a public bug-bounty program. Responsible disclosure is welcome at the security email above. Do not access customer data or disrupt production services.
Certifications and marks
ISO 9001, ISO 27001, SOC 2, ONVIF and similar marks may appear in marketing for orientation. Ask sales@orionalerts.com for any certificate, scope, and validity evidence that applies to a specific entity or engagement.
Subprocessors and trust center
Website-related processors currently reflected in code or planned for production:
- Website hosting (production provider) — Serve the public website and application APIs. (planned)
- CDN / edge delivery (when configured) — Deliver static assets and edge caching when configured. (planned)
- Google (reCAPTCHA) — Abuse prevention on demo lead submissions. (active)
- OrionAlerts sales operations — Respond to leads via sales@orionalerts.com; durable CRM not integrated (active)
- Application monitoring (when configured) — Operational monitoring and error diagnostics when configured. (planned)
A customer trust center and signed product subprocessor list are not published on this website yet. For website processing see the Privacy Policy. For enterprise deployments, request details via sales@orionalerts.com.
Security contact
Security: security@orionalerts.com. Privacy: privacy@orionalerts.com. General: sales@orionalerts.com.