Security
Every claim below is a mechanism, not an intention — because “we take security seriously” is what every company says the week before it doesn’t.
Last updated 24 September 2026Staff cannot read your location
This is the difference that matters. Almost every product in this category has an internal tool that can see any customer's data, guarded by a policy and an access log. A policy is a promise; a missing grant is a fact.
Every view is written down
It covers views by your own family too, not only by us. If somebody in your circle opened your location at 2am, that is in the log you can read, and this was a deliberate choice: the person most likely to misuse a family tracker is in the family.
How the data is protected
Accounts and sessions
Dependencies
Every third-party package, direct and indirect, is checked before it enters the build: how widely used it is, whether its publisher changed recently, and whether it runs code at install time. Lockfile checksums are verified on every install, and a hash that changes without a version change stops the build rather than being regenerated.
The application does not hand its whole environment to every process. Each part receives only the values it needs, so a compromised package cannot read a credential belonging to something else.
What we have not done yet
Orbities has not been through an external penetration test or a formal certification such as SOC 2 or ISO 27001. Saying so is more useful than a badge: if you are choosing between products on this basis, you now know where we are.
Reporting a problem
Write to [email protected] with enough detail to reproduce it. We will acknowledge within two business days and tell you what we are doing.
We will not pursue anybody who reports a flaw in good faith, does not access data belonging to other people, and gives us a reasonable chance to fix it before publishing.