Security approach
PanoOrbit applies security controls appropriate to a multi-tenant SaaS product and reviews them as the platform evolves. Security is a shared responsibility between PanoOrbit, customers and the infrastructure/services used to deliver the platform.
Authentication and access control
Access to private application areas is authenticated. Product permissions and roles are used to limit actions to authorised users. Customers are responsible for choosing trusted administrators, protecting credentials and removing access when team members no longer require it.
Agency data isolation
PanoOrbit is designed so agency-scoped operational information is accessed in the context of the authorised agency. Backend access controls should be enforced independently of what is visible in the user interface. Public tour content is treated separately from private agency administration data.
Transport and infrastructure
Production traffic should be served over HTTPS/TLS. Infrastructure, database, storage and delivery services are configured with access controls appropriate to their role. Administrative credentials, API keys and secrets should not be committed to public source code and should be managed through protected configuration.
Property media and public tours
360 degree media and property assets may need to be delivered to visitors viewing a public tour. Customers should avoid uploading confidential material to public-tour assets. PanoOrbit may apply subscription, publishing or access controls to tours, but a published public experience should be treated as content intended for its audience.
Logging, monitoring and background processing
Operational logs, audit records and background-job information may be used to diagnose errors, investigate suspicious activity and support reliable processing. Access to such information should be limited to operational need.
Backups and recovery
PanoOrbit may use backup and recovery mechanisms for critical service data according to operational requirements. Backups are not a substitute for customers retaining copies of source property assets and business records they are independently required to keep.
Incident handling
Suspected security incidents are assessed based on scope, affected systems and available evidence. Where notification is required by applicable law or contract, PanoOrbit will take reasonable steps to provide appropriate notice.
Security reporting
If you believe you have found a vulnerability, send details to support@panoorbit.com. Do not access, modify, download or expose data that is not yours, disrupt the service, use destructive testing or publicly disclose an unresolved issue before allowing reasonable time to investigate.
No unearned certification claims
Unless PanoOrbit explicitly publishes a current certification or audit report, the service should not be represented as SOC 2 certified, ISO 27001 certified, PCI DSS certified or otherwise independently certified merely because an infrastructure or payment provider may hold its own certifications.
