How invest.Orbsam stores and protects data. Orbsam is run by a tiny team; this page describes the technical controls in the app and what still depends on how the instance is hosted.
Each user owns their own portfolios, trades, accounts, and notes. Route model binding scopes records to the signed-in user, so one account cannot open another user’s data through the web UI.
Holdings quantities, trade prices, cash amounts, research notes, asset symbols, and related portfolio data are stored as plaintext so the app can aggregate totals, filter, and refresh prices. This is not a zero-knowledge vault: decryption for encrypted fields uses the server-held application key.
Anyone with server, database, or application-key access can read stored data, including decrypting encrypted columns. There is no “view as user” feature in the product UI.
When ADMIN_EMAILS is set, those accounts can see a user list and AI billing metadata (names, emails, credit usage). They cannot open portfolios or trades through the admin UI. Admin accounts must enable two-factor authentication before using admin routes.
Successful writes on portfolio, account, asset, import, and related routes are written to an access log with timestamp, actor, route, resource, IP address, and a checksum chained to the previous entry (under a database lock). Page reads are not logged so navigation stays fast. The log supports review; it does not prevent someone with database access from reading data.
Optional TOTP two-factor authentication is available under Settings → Security. Recovery codes are shown once at setup and stored hashed. Login and 2FA challenge endpoints are rate-limited (5 attempts per minute per email/user and IP).
Broker and CAS imports are parsed in memory. Fields such as postal address, date of birth, email, phone, bank account numbers, Aadhaar, and full PAN are stripped before review; nothing is written until you confirm. If you use filing summarize, filing compare, or other cloud AI features, document content is sent to the configured model providers. Disable AI in Settings to avoid that egress.
Disk encryption at rest, backup encryption, region, and retention are properties of the host environment, not of this application code. Confirm those with whoever operates the deployment.
Last updated October 2026.