Environment variables
Server-only variables must never be prefixed withVITE_ or shipped to a device client.
Public clients may receive only the Supabase URL, publishable key, gateway origin, policy version, and public verification keys. Device private keys are generated and stored in the OS keystore.
Deployment and rollback
1
Migrate and test
Apply the migration to a branch or local database, run RLS and replay tests, then security advisors.
2
Deploy gateway disabled
Deploy the gateway with execution globally disabled.
3
Deploy read-only views
Deploy read-only dashboard and audit views.
4
Enroll test devices
Enroll internal test devices and enable only low-risk capabilities.
5
Roll out by capability flag
Roll out by capability flag, never by generic account-wide control.
Incident response
Contain with global lockdown, session revocation, device revocation, and signing-key rotation. Preserve append-only audit evidence, notify affected users, scope exposed capabilities and data, remediate, and document regulatory notification decisions.Retention defaults
Pre-release checklist
- Independent threat model and penetration test completed
- RLS isolation, signature forgery, replay, brute-force, confirmation bypass, traversal, symlink, XSS, and CSRF tests pass
- Native signing, sandboxing, permissions, accessibility, and store-policy review completed per platform
- Accessibility audit and emergency-stop offline test pass
- Dependency, secret, and static analysis findings triaged
- Terms, privacy, DPA, subprocessors, retention, consent, organization notices, minors flow, and transfer mechanism reviewed by qualified counsel in every launch jurisdiction
These documents are implementation templates and must be reviewed by a qualified lawyer for every jurisdiction where Orbit operates.