Security at Saral Orbit
People trust us with Aadhaar copies, photographs, signatures and certificates. This page tells you, without big words, what we do to protect them — and what we cannot promise.
Effective from 10 October 2026
2. How we protect your files
- Processed on our own server. Your document is handled by our own software and is not sent to any other company’s service or AI tool.
- Deleted quickly. The original upload is removed as soon as the work is done. If an error leaves anything behind, a cleaner runs every 10 minutes and removes uploads older than 2 hours and results older than 4 hours (Sign Document files: 8 hours).
- Only you can fetch the result. Every result is tied to the browser session or account that created it. If someone else gets hold of a download link, the server refuses it. Result file names are long, random and cannot be guessed.
- Files are checked on arrival. We reject empty files and files whose contents do not match what they claim to be, and we apply size limits for each plan.
- Nobody browses your files. Our staff do not open uploaded files, and we do not use them for advertising or to train AI models.
- Errors do not leak. If something fails, you see a short message — not our internal file paths or system details.
3. Connection & browser protection
- HTTPS. Traffic between your browser and saralorbit.in is encrypted, and the site tells browsers to keep using HTTPS (HSTS).
- Safe cookies. The sign-in cookie is marked HttpOnly (page scripts cannot read it), SameSite (it is not sent with requests started by other sites) and Secure on HTTPS.
- Forged-request protection. Actions that change something (sign in, upload, pay, delete) are accepted only when they come from our own pages.
- Browser security headers. We switch off browser features the site does not need (camera, microphone, location), stop other sites from putting ours inside a frame, and block content-type guessing.
4. Account protection
- Hashed passwords. Passwords are stored only as a one-way scrambled value (bcrypt). Not even we can read them. New passwords must pass a strength check.
- Guessing is slowed down. Repeated wrong passwords, codes or reset requests are rate-limited. Sign-in takes the same time whether or not an email exists, so attackers cannot learn who has an account.
- One-time codes. Email codes expire in 10 minutes and are stored hashed. Password-reset links are single-use and expire.
- Sign in with Google or Microsoft is available, so you do not have to create another password. We receive only your name and verified email.
- Device limit and sign-out. Each plan allows a set number of signed-in devices. Changing your password signs you out of your other devices.
- Admin accounts are protected with two-step verification using an authenticator app.
5. Payment safety
- Payments are taken on the page of a licensed payment gateway (such as Razorpay, Cashfree, PayU or PhonePe). Your card number, UPI PIN and bank details are typed there and never reach our servers.
- A plan is switched on only after the gateway confirms the payment to our server, not just because a browser page says “success”.
- We keep only a payment reference, the amount, the status and an invoice number.
- Our secret keys for the gateways are kept encrypted in the database.
6. Our systems
- Encrypted backups. A copy of our account and payment data is made every day and encrypted before it is saved, so a stolen backup file is unreadable.
- Logs for important actions. Sign-ins, account changes and admin actions are recorded in a security log (kept up to a year) so we can investigate misuse.
- Automatic cleanup. Old temporary files, expired sessions and out-of-date records are removed on a schedule, so we do not hold data longer than needed.
- Updates. We keep our software libraries up to date and fix security problems as we find them.
7. Our people
Only the few people who must run the service can reach the admin area, each with their own sign-in and with only the permissions their work needs. Admin actions are logged.
8. What we do not claim
9. Tips to stay safe
- Use a strong password that you use nowhere else, or sign in with Google/Microsoft.
- On a shared or cyber-café computer, always log out and close the browser when you finish, and download your result before you leave.
- Keep your own copy of important documents — we delete ours on purpose.
- Only use saralorbit.in. We never ask for your password, OTP, UPI PIN or card number on WhatsApp, calls or email.
- Blur or hide parts of a document you do not need to share.
10. Found a security problem?
Please tell us first so that we can fix it before it affects anyone. Write to support@saralorbit.in with the subject “Security”, and describe what you found and how to repeat it. Do not access other people’s data, do not harm the service, and give us reasonable time to fix the problem before you share it publicly. We will acknowledge your report within 2 working days and keep you updated. If you believe your own account is at risk, change your password and write to us immediately.
See also: Privacy Policy · Cookie Policy · Terms & Conditions




