Security
Last updated September 20, 2026
This page describes how Orrery Systems LLC protects HALO and the information our customers trust it with. For security documentation or a completed security questionnaire, contact security@orrerysystems.app.
Compliance
HALO is built on infrastructure and payment providers that maintain independently audited SOC 2 Type II and ISO 27001 programs, and payments are handled by a PCI DSS Level 1 certified processor. Our own controls are designed around the SOC 2 Trust Services Criteria for security, availability, and confidentiality. Security documentation is available to customers and prospective customers on request.
Data we collect and store
What HALO collects, how it is used, and who it is shared with are described in our privacy policy and subprocessors list.
Infrastructure
Hosting. HALO is hosted in the United States with a leading cloud provider whose data centers maintain strict physical and logical access controls and are regularly assessed by independent auditors. Customer data is never publicly accessible.
Encryption. All data is encrypted in transit with HTTPS/TLS and encrypted at rest. Credentials and keys are stored in a dedicated, access-controlled secrets vault, never in source code.
Access. Administrative access to production is limited to authorized personnel, uses individual accounts with multi-factor authentication, and is logged.
Application security
Single sign-on. Every HALO user signs in through their organization’s own identity provider, so your organization controls who has access and can enforce multi-factor authentication. HALO does not store user passwords.
Least privilege. Each connection to a customer system is granted only the permissions it needs, read-only wherever possible, and administrative actions in HALO are recorded in an audit log.
On-site collectors
The small collector devices placed at customer sites connect outbound only, so no customer network is exposed to the internet. Each collector is individually authenticated and can be revoked on its own, has read-only access to the systems it monitors, and runs on a hardened, automatically updated operating system.
Payments
HALO invoices are paid through Stripe, a PCI DSS Level 1 certified payment processor. Card and bank account details are entered on pages hosted by Stripe and never pass through or rest on HALO’s servers.
Secure development
Every change to HALO is reviewed and passes automated testing and security scanning before it can reach production, and infrastructure changes follow the same process.
Monitoring and incident response
HALO is monitored continuously with automated alerting. If a security incident affects customer data, we will notify affected customers without undue delay and within the time the law requires, and share what happened and what we are doing about it.
Business continuity
Customer data is backed up automatically and encrypted, and the service is designed to be restored quickly in the event of a failure or regional outage.
Reporting a vulnerability
If you believe you have found a security vulnerability in HALO or this website, email security@orrerysystems.app with enough detail for us to reproduce it. We will acknowledge your report within two business days and keep you informed as we fix it. We will not pursue legal action against anyone who reports in good faith, avoids accessing or changing customer data, and gives us reasonable time to fix the issue before disclosing it.