> ## Documentation Index
> Fetch the complete documentation index at: https://documentation.orbitdev.org/llms.txt
> Use this file to discover all available pages before exploring further.

# Orbit Control Operations, Deployment, and Release Gates

> Operational procedures for Orbit Control: environment variables, deployment steps, rollback, incident response, retention defaults, and the pre-release checklist.

This page documents the operational procedures for running and releasing Orbit Control. It covers environment variable classification, deployment and rollback steps, incident response, retention defaults, and the pre-release checklist that must pass before any launch.

## Environment variables

Server-only variables must never be prefixed with `VITE_` or shipped to a device client.

| Server-only | Purpose |
| - | - |
| `CONTROL_COMMAND_SIGNING_PRIVATE_KEY` | Signs device-bound commands |
| `CONTROL_PAIRING_PEPPER` | Hardens pairing-code digest |
| `CONTROL_AUDIT_REGION_SALT` | Salts audit region identifiers |
| `CONTROL_NOTIFICATION_CREDENTIALS` | Gateway notification credentials |

Public clients may receive only the Supabase URL, publishable key, gateway origin, policy version, and public verification keys. Device private keys are generated and stored in the OS keystore.

## Deployment and rollback

<Steps>
  <Step title="Migrate and test">
    Apply the migration to a branch or local database, run RLS and replay tests, then security advisors.
  </Step>

  <Step title="Deploy gateway disabled">
    Deploy the gateway with execution globally disabled.
  </Step>

  <Step title="Deploy read-only views">
    Deploy read-only dashboard and audit views.
  </Step>

  <Step title="Enroll test devices">
    Enroll internal test devices and enable only low-risk capabilities.
  </Step>

  <Step title="Roll out by capability flag">
    Roll out by capability flag, never by generic account-wide control.
  </Step>
</Steps>

Rollback disables AI execution and sensitive capabilities first, cancels queued commands, revokes sessions if compromise is suspected, and rolls application code back. Do not reverse an audit migration by deleting evidence. Use a forward migration to disable affected functions and preserve records.

## Incident response

Contain with global lockdown, session revocation, device revocation, and signing-key rotation. Preserve append-only audit evidence, notify affected users, scope exposed capabilities and data, remediate, and document regulatory notification decisions.

<Warning>
  Never place secrets, pairing codes, device content, or raw credentials in incident logs.
</Warning>

## Retention defaults

| Data type | Default retention |
| - | - |
| Pairing requests | Remove or irreversibly redact codes after expiry |
| Command payloads | Minimize and redact after operational need |
| Audit security metadata | Retain according to documented legal and security need |
| Camera, microphone, screen, location content | Do not store by default |
| Temporary assistance artifacts | Delete automatically at session end |

## Pre-release checklist

* Independent threat model and penetration test completed
* RLS isolation, signature forgery, replay, brute-force, confirmation bypass, traversal, symlink, XSS, and CSRF tests pass
* Native signing, sandboxing, permissions, accessibility, and store-policy review completed per platform
* Accessibility audit and emergency-stop offline test pass
* Dependency, secret, and static analysis findings triaged
* Terms, privacy, DPA, subprocessors, retention, consent, organization notices, minors flow, and transfer mechanism reviewed by qualified counsel in every launch jurisdiction

<Note>
  These documents are implementation templates and must be reviewed by a qualified lawyer for every jurisdiction where Orbit operates.
</Note>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.