Skip to main content
Orbit Control is the security foundation and safe-MVP specification for device-bound command execution. This page covers the trust boundaries, data flow, primary threats and controls, the capability and risk matrix, platform limitations, and residual risks that require specialist review. Sensitive device execution is not production-enabled.
Sensitive device execution is not production-enabled. This architecture is a security foundation and safe-MVP specification.

Trust boundaries and data flow

The command lifecycle crosses three trust zones: the authenticated dashboard, the command gateway, and the paired device. Each zone enforces policy independently.
1

Dashboard proposes action

The authenticated dashboard proposes a typed action. Retrieved content is data, never policy.
2

Gateway validates and gates

The command gateway validates identity, current session, ownership, capability, risk, consent, and rate limits.
3

Preview and confirmation

Medium actions show a preview. High actions require confirmation plus AAL2 step-up. Critical actions add a second confirmation.
4

Gateway signs device-bound command

The gateway signs a device-bound command with a unique nonce and a lifetime of at most five minutes.
5

Device verifies independently

The paired device independently verifies signature, nonce, expiry, device ID, current local grant, and local approval.
6

Device executes least-privileged action

The device uses the least-privileged OS API, keeps sensitive access visible, and returns a bounded result.
7

Audit event is appended

The gateway appends an audit event. Models and ordinary clients cannot modify audit rows.
Cloud failure must fail closed. The local device retains Stop Control and Lockdown controls when offline.

Primary threats and controls

Capability and risk matrix

Terminal access never means a generic shell. A separately configured command policy must bind executable, arguments, working directory, duration, and output limits.

Platform capability matrix

Residual risks

The following risks require specialist review:
  • Native-agent sandbox escapes
  • OS accessibility abuse
  • Signing-key compromise
  • TURN/WebRTC metadata exposure
  • Organization consent validity

Monorepo target

The current repository remains operational while migration proceeds toward:
  • apps/web
  • apps/desktop
  • apps/android
  • apps/ios
  • services/gateway
  • services/notifications
  • packages/control-sdk
Do not duplicate security policy between apps. The shared SDK defines schemas, while the gateway and native agent each enforce policy independently.