Security & Transparency
We built Sovereign Orbital for operators who take sovereignty seriously. Your data gets the same treatment as your orbit.
Your Data, Your Orbit
How Your Account Is Protected
Data Isolation
Each account sees only its own data. There is no shared state between users.
API routes validate your session on every request. Pre-orders, subscriptions, and account details are scoped to your email and user ID. No cross-account queries are possible through normal platform access.
Sessions are cryptographically signed โ a tampered or forged session token is rejected at the server.
What We Collect and Why
| Data | Reason | Retention |
|---|---|---|
| Name | Order fulfillment | Until deletion request |
| Account + communications | Until deletion request | |
| Country | Launch planning | Mission fulfillment period |
| IP / logs | Security / debugging | 30 days (Vercel infra) |
What We Never Do
Cookies
We use exactly one cookie:
so_sessionYour Controls
You are in control of your data at all times:
- Delete your accountEmail hello@sovereignorbital.org
- Export your dataEmail hello@sovereignorbital.org
- Enable / disable 2FAAccount page โ Security section
- Cancel your intentAccount page or email us
- Correct your informationEmail hello@sovereignorbital.org
Infrastructure
Responsible Disclosure
Found a security vulnerability? We want to hear from you.
Email engineering@sovereignorbital.org with a description of the issue. We respond within 48 hours. We ask that you give us reasonable time to investigate and patch before public disclosure.
We do not currently offer a bug bounty program, but we will acknowledge your contribution.
Compliance
See our Privacy Policy for full details on rights and data handling.