How Orbit protects your tokens and data
Layered security:
- Encrypted tokens: your channels' access tokens are stored with AES-256-GCM encryption — they're never in plain text, not even in the database;
- Authenticated webhook: every Meta event is validated by cryptographic signature (HMAC) before processing — forged events are rejected;
- Per-account isolation: each workspace only accesses its own data, enforced by database access rules;
- Auditable history: messages are only written by the server — not even a member of your team can alter the history.
More at Security.
8. Privacy and Data
Didn't resolve it? support.orbit@expertbr.com
← Back to Help