TRUST · SECURITY
A route to report a flaw. No certificate saying you won't need it.
Reporting a flaw should not require finding a person first. The machine route below is the canonical one, it is checked by anyone with the URL, and it sits beside the honest list of what we hold and do not hold about this platform — because the second list is exactly what a security-minded reader wants before they act on the first.
Where a report goes.
/.well-known/security.txt, published on the cell at https://id.orbis.id/.well-known/security.txt, is the machine-readable route (RFC 9116): a contact, and an expiry the cell regenerates on every response so the file cannot silently go stale. A person reading this page rather than a scanner can use the same contact by hand.
Fetched directly this session, the file's own fields: Contact: mailto:security@orbis.id,
an Expires field one year out from the moment it was requested, and a Canonical field naming the exact URL it was fetched from. The expiry moving with
the request, rather than sitting fixed in a file nobody revisits, is the whole mechanism that
keeps this route from going stale-invalid without anyone noticing.
What happens after you send one.
We do not publish a promised acknowledgement time on this page, because we have not measured one long enough to stand behind it, and a made-up number would be worse than none. What we can say plainly: a report is read by a person, not routed into a queue nobody owns, and a confirmed flaw gets fixed before it gets announced. Alerting is not an SLA and this page will not blur the two.
What we hold, and what we do not.
- Third-party code audit
- Not commissioned. No published audit of this codebase exists.
- ISO 27001
- Not held.
- SOC 2
- Not held.
- Verifiable-credential conformance, outside-tested
- Not held. every component the profile names is implemented here. The conformance suite has not been run, so the profile is not claimed — only the parts are, and each part has its own row above.
- eIDAS 2.0 / EUDI conformity assessment
- built on the wire the reference architecture selects — SD-JWT VC carried over OpenID4VCI and OpenID4VP. Conformity assessment has not been undertaken. That is a decision, on the record, not an oversight.
The HAIP and eIDAS rows above are quoted from _evidence.ts §1, checked 2026-08-27.
Before you go any further.
The machine-readable reporting route is live on the cell and answers today. It has no row of its own in the register this build reads from yet, which is why the register below does not yet carry it as a state.
The register holds 17 live · 2 partial · 2 planned · 5 not yet.
1 of the 1 capabilities this page depends on have no row in the register yet, so this page will not print a state for them. They are named rather than dropped, because a slice that silently shortens itself is the same defect as a claim with no receipt.
- security-txt
The register route serves, but it carries no row for these yet. List what it does carry:
curl -s https://id.orbis.id/api/site/register | jq -r '.entries[].slug' Straight answers.
- Do you hold ISO 27001 or SOC 2?
- No. Neither has been undertaken.
- Has anyone outside ORBIS audited this code?
- No. No third-party audit has been commissioned or published.
- Do you promise a response time for a report?
- No. We would rather publish nothing than a number we invented, and alerting somebody quickly is not the same claim as a contractual response time.
- Is the reporting route metered or gated behind an account?
- No. It is a published file at a fixed path, readable by anyone and anything.
No certification, no audit, no SLA, no promised response time. Every one of those is a thing we could buy, commission or invent this quarter, and each would make this page look considerably more reassuring than the system currently deserves. What we have instead is a route that works and an expiry that cannot go stale — and you can fetch both right now.
Do not trust us. Check us.