Tenant isolation from the foundation
Customer records carry an organization boundary, and authorization is resolved by the server rather than accepted from browser input.
Join the betaSecurity
Project Orion is designed so customer identity, connected accounts, and planning data remain inside explicit boundaries. The private beta advances only when those boundaries are tested and the required controls are ready.
Customer records carry an organization boundary, and authorization is resolved by the server rather than accepted from browser input.
People and services receive only the narrow capability needed for an approved task. Sensitive operations require separate authorization and audit evidence.
Connected account credentials are encrypted and stay out of browser storage, logs, analytics, screenshots, fixtures, and source control.
The first Amazon pilot is limited to approved nonrestricted orders, listings, and inventory data. Buyer contact, address, and payment data are not requested.
Authentication, Amazon connection, import execution, and public signup use separate controls. A successful connection does not automatically start an import.
Source data is kept only for the approved purpose and no longer than the stated retention period. Verified deletion and disconnect requests follow bounded operational procedures.
Private beta posture
Project Orion does not describe a control as live merely because it exists in local code. Production access, infrastructure, provider credentials, monitoring, backup, and recovery each require their own review before a customer connection is activated.
For security questions, contact hello@projectorion.io.