ORBIS.ID
You are on Anyone PUBorbis.id

LEGAL · DATA PROCESSING ADDENDUM

A processing addendum needs two signatures. Neither exists yet.

A DPA sets the terms under which ORBIS.ID processes data on behalf of an organization that issues credentials through it — sub-processors, security measures, breach notice, international transfer terms. None of that can be signed without the legal entity itself, which is not published yet, so this page does not draft one in the meantime. What is already true: no operation in the platform hands a private signing key to anyone, including us — /company names exactly what we can and cannot see.

What this page is missing, named plainly.

A data processing addendum has two required facts this page cannot yet supply: the legal entity that would be the processor, and the document itself. Both are named as absent rather than filled with placeholder legal language.

The register holds 17 live · 2 partial · 2 planned · 5 not yet.

2 of the 2 capabilities this page depends on have no row in the register yet, so this page will not print a state for them. They are named rather than dropped, because a slice that silently shortens itself is the same defect as a claim with no receipt.

  • legal-entity-name
  • data-processing-addendum

The register route serves, but it carries no row for these yet. List what it does carry:

curl -s https://id.orbis.id/api/site/register | jq -r '.entries[].slug'

A processing addendum signed by nobody protects nobody.

Straight answers.

Can an organization sign a DPA with ORBIS.ID today?
No.
Does the platform already limit what data it can see, even without a signed DPA?
Yes — the key-custody architecture is built, not promised, and it is described on the company page regardless of what is or is not signed.

Do not trust us. Check us.