Home / Security & Trust
Security & trust · whitepaper v1

Why you can trust us with your project files.

This is the question professional teams ask before handing a file system their work. We answer it plainly: how Orbifs is built, where data lives, how access is controlled, and how files recover. Where something is standard, we say so. Where it’s still being finalised, we mark it — and don’t claim it as done.

Status: launch preparation

Orbifs is preparing for launch. The items marked being finalised below are genuinely not yet locked, and we will not present them as complete until they are. This whitepaper is versioned and dated; each update is published.

What’s standard today

  • EU hosting in France, replicated across multiple data centres for resilience
  • Encryption at rest as standard
  • Immutable, tamper-resistant version history
  • Accounts, roles and per-project permissions on a least-privilege model
  • Multi-factor authentication on user sign-in
  • Immutable version history and restore of prior versions and deleted files

Being finalised — not yet claimed

  • Encryption in transit — protocol and configuration are being verified being finalised
  • Key management — custody model and any customer-managed-key option being finalised
  • Backup RPO/RTO targets and the published restore SLA being finalised
  • Security certifications — none claimed; see the roadmap below being finalised
Where your data lives

Hosted in Europe, in France.

Customer data is stored in European data centres in the Paris (France) region, on infrastructure operated by a European cloud provider.

PropertyDetail
Hosting regionParis, France (EU)
ProviderA European cloud provider — named in our subprocessor list, on request
ResilienceReplicated across multiple data centres for durability
RecoveryImmutable, tamper-resistant version history
Data transferNo data-transfer fees for customers

Full residency, jurisdiction and subprocessor detail is in the Data Residency & Sovereignty Statement.

Encryption & key management

Stated plainly, with current status.

LayerCurrent position
At rest Standard  Encryption at rest is standard for all customer data.
In transitbeing finalised  Expected to use standard TLS for client–service connections; being verified before any firm claim.
Key managementbeing finalised  Model for key custody and any customer-managed-key option not yet finalised.
Zero-knowledgeNot offered today; tracked as a possible future capability, not a current claim.

We will not assert end-to-end or zero-knowledge encryption unless the design genuinely provides it. This section is expanded with protocol versions, cipher configuration and the key-management model once confirmed.

Identity & access

Least privilege, by role.

Access to projects runs through user accounts, roles and per-project permissions in the admin console. Users and administrators get the access their role needs — no more.

  • Multi-factor authentication for user sign-in
  • SSO / SAML for centralised identity on Business and above
  • Administrator, editor and guest/client roles with project-level permissions
  • Guest and external-partner access granted and revoked per project
Recovery & backups

Immutable versions, recoverable files.

Versions are kept immutable and tamper-resistant through your plan’s retention window. You can restore prior versions and deleted files — the basis for recovering from mistakes and ransomware.

  • Retention from 90 days (Studio) up to policy-based (Business)
  • Restore tested as part of every pilot and onboarding
  • Published RPO/RTO targets being finalised
  • We say “recoverable,” never “ransomware-proof”
Data processing & GDPR

Processed in the EEA, under the GDPR.

Archi Systems AS is established in Norway, within the EEA, and applies the GDPR. Hosting customer data in France (EU) involves no transfer of personal data outside the EEA.

DPA on request

A Data Processing Agreement is available for customers, alongside our privacy policy and technical & organisational measures (TOMs).

Short, EU-based subprocessor list

Kept short and shared in full on request. Billing data is handled separately from your project files, which never leave EU storage.

NIS2-aware

Built with EU security frameworks in mind, including raised expectations on backup, recovery and access control.

For the full picture of where data lives and who can touch it, read the Data Residency & Sovereignty Statement →

Certification roadmap

We display a trust mark only once we’ve earned it.

A non-negotiable principle: do not claim a certification before it exists. Here is what we’re pursuing, and in roughly what order.

TargetWhat it signalsStatus
ISO/IEC 27001Mature information-security management system — our intended anchor.pursuing
SOC 2 (Type I → II)Audited security controls over time; valued by larger and international customers.pursuing
Cyber EssentialsBaseline cyber hygiene — a lighter, quicker early signal.candidate
ENS / SecNumCloud-adjacentPublic-sector and French sovereign-cloud expectations, per target market.candidate

For the record

No certifications are claimed yet. A short, EU-based subprocessor list keeps our scope simple, and the policy set behind this page — incident response, backup/restore, data residency, GDPR — is in place or under legal review. We’ll publish each certification only once formally achieved.

In short

Built on European infrastructure, described honestly.

France · EU
Hosted in Europe across multiple data centres
Immutable
Tamper-resistant version recovery
MFA · SSO
MFA for all; SAML on Business+
EU-only
All data processing in the EU/EEA

Need our DPA, subprocessor list or a completed security questionnaire? We keep an answer bank ready. Request security documents →

Pilot offer

Prove the recovery story yourself.

Every pilot includes a restore test: we restore a prior version and a deleted file so you see recovery work on your own data before you commit.