Our security architecture

How invest.Orbsam stores and protects data. Orbsam is run by a tiny team; this page describes the technical controls in the app and what still depends on how the instance is hosted.

Tenant isolation

Each user owns their own portfolios, trades, accounts, and notes. Route model binding scopes records to the signed-in user, so one account cannot open another user’s data through the web UI.

Encryption

  • HTTPS - Production traffic is forced to HTTPS, with HSTS enabled.
  • Database TLS - In production the app requires a TLS connection to MySQL/MariaDB or PostgreSQL (CA configured; the app will not boot if TLS is required and missing). SQLite local use is exempt.
  • Passwords - Stored as bcrypt hashes.
  • Two-factor secrets - TOTP secrets and recovery-code hashes are encrypted at rest (AES-256 via the application key).
  • Owner and account identifiers - Owner names and account names/codes are encrypted at the column level with the same application key.
  • Sessions - Session payloads are encrypted in production by default.

What stays readable in the database

Holdings quantities, trade prices, cash amounts, research notes, asset symbols, and related portfolio data are stored as plaintext so the app can aggregate totals, filter, and refresh prices. This is not a zero-knowledge vault: decryption for encrypted fields uses the server-held application key.

Operator and admin access

Anyone with server, database, or application-key access can read stored data, including decrypting encrypted columns. There is no “view as user” feature in the product UI.

When ADMIN_EMAILS is set, those accounts can see a user list and AI billing metadata (names, emails, credit usage). They cannot open portfolios or trades through the admin UI. Admin accounts must enable two-factor authentication before using admin routes.

Access logging

Successful writes on portfolio, account, asset, import, and related routes are written to an access log with timestamp, actor, route, resource, IP address, and a checksum chained to the previous entry (under a database lock). Page reads are not logged so navigation stays fast. The log supports review; it does not prevent someone with database access from reading data.

Authentication

Optional TOTP two-factor authentication is available under Settings → Security. Recovery codes are shown once at setup and stored hashed. Login and 2FA challenge endpoints are rate-limited (5 attempts per minute per email/user and IP).

Imports and AI

Broker and CAS imports are parsed in memory. Fields such as postal address, date of birth, email, phone, bank account numbers, Aadhaar, and full PAN are stripped before review; nothing is written until you confirm. If you use filing summarize, filing compare, or other cloud AI features, document content is sent to the configured model providers. Disable AI in Settings to avoid that egress.

Application hardening

  • Security headers: frame protection, MIME sniffing, Referrer-Policy, Permissions-Policy; HSTS in production
  • Passwords, 2FA codes, and invite codes are not flashed back on validation errors

Hosting and backups

Disk encryption at rest, backup encryption, region, and retention are properties of the host environment, not of this application code. Confirm those with whoever operates the deployment.

Last updated October 2026.