Skip to main content
This page documents the operational procedures for running and releasing Orbit Control. It covers environment variable classification, deployment and rollback steps, incident response, retention defaults, and the pre-release checklist that must pass before any launch.

Environment variables

Server-only variables must never be prefixed with VITE_ or shipped to a device client. Public clients may receive only the Supabase URL, publishable key, gateway origin, policy version, and public verification keys. Device private keys are generated and stored in the OS keystore.

Deployment and rollback

1

Migrate and test

Apply the migration to a branch or local database, run RLS and replay tests, then security advisors.
2

Deploy gateway disabled

Deploy the gateway with execution globally disabled.
3

Deploy read-only views

Deploy read-only dashboard and audit views.
4

Enroll test devices

Enroll internal test devices and enable only low-risk capabilities.
5

Roll out by capability flag

Roll out by capability flag, never by generic account-wide control.
Rollback disables AI execution and sensitive capabilities first, cancels queued commands, revokes sessions if compromise is suspected, and rolls application code back. Do not reverse an audit migration by deleting evidence. Use a forward migration to disable affected functions and preserve records.

Incident response

Contain with global lockdown, session revocation, device revocation, and signing-key rotation. Preserve append-only audit evidence, notify affected users, scope exposed capabilities and data, remediate, and document regulatory notification decisions.
Never place secrets, pairing codes, device content, or raw credentials in incident logs.

Retention defaults

Pre-release checklist

  • Independent threat model and penetration test completed
  • RLS isolation, signature forgery, replay, brute-force, confirmation bypass, traversal, symlink, XSS, and CSRF tests pass
  • Native signing, sandboxing, permissions, accessibility, and store-policy review completed per platform
  • Accessibility audit and emergency-stop offline test pass
  • Dependency, secret, and static analysis findings triaged
  • Terms, privacy, DPA, subprocessors, retention, consent, organization notices, minors flow, and transfer mechanism reviewed by qualified counsel in every launch jurisdiction
These documents are implementation templates and must be reviewed by a qualified lawyer for every jurisdiction where Orbit operates.