Security & privacy
ISO 27001 + SOC 2 certified, India-resident data, AI guardrails that keep PII out of prompts, and a per-student audit log.
Student data is sensitive, so Orbit is built privacy-first — certified, India-resident, and fully auditable.
| Control | Detail |
|---|---|
| Certifications | ISO 27001 and SOC 2 Type II. |
| Compliance | DPDPA — India’s data-protection act. |
| Data residency | Stored in India (Mumbai + Bangalore regions). |
| AI guardrails | No PII (studentId, email) is ever sent in an AI prompt. |
| Audit | Every admin action is recorded with actor and payload (see Admin console). |












