Security
If you hire an IT company, you hand it the keys. That makes us part of your attack surface, not just your defence against it — and it means you are entitled to ask how we are run, not only what we sell. This page answers that for the website. Ask us the same questions about everything else.
Last updated 16 September 2026. Covers orbitpointtech.com.
The short version. This website holds no accounts, no passwords and no customer records, sets no cookies and runs no tracking. The less it carries, the less there is to lose — and that is a deliberate design decision rather than an accident of being small.
Most of the damage done to small businesses through their IT provider does not come from the provider being attacked directly. It comes from the provider having standing access to everything and treating that access casually — shared passwords, no multi-factor, remote tools left open, a support mailbox anyone can spoof.
You cannot audit us from a web page. What you can do is ask specific questions and see whether the answers are specific back. Below is us going first.
It is a set of static files. There is no database behind it, no login, no admin panel and no content management system. There are no user accounts to compromise because there are no user accounts, and nothing to dump because nothing is stored.
The practical effect is that the most common ways a small business website gets breached — an out-of-date plugin, a stolen admin password, an abandoned staging site — do not apply here.
The password tester is the one that matters here. It runs entirely inside your browser and transmits nothing — not to us, not to anyone. We are aware of the irony of a security company asking you to type a password into its website, which is why the answer needs to be checkable rather than reassuring. Turn off your internet connection and it still works.
The email security checker sends the domain you type to a public DNS resolver, because that is the only way to read a domain's published records. That is all it sends.
Those tools read data that other people control — a DNS record is whatever the domain owner published, which means it is untrusted input. The results are escaped before they are displayed, so a hostile record cannot turn into code running on this site. That was found and fixed in a review of our own tools rather than reported to us.
These are the outside companies with any part in this website working. It is a short list on purpose.
This list covers the website. If you are evaluating us as a supplier and want the full list of systems that would touch your data under an agreement, ask and we will give it to you in writing rather than making you infer it from a web page.
Before you sign anything with any IT provider, including us, these are worth asking. We will answer all of them in writing:
If a provider is vague on any of these, that is information too.
If you have found something wrong with this website — a flaw in a tool, something exposed that should not be, anything that looks off — please tell us at [email protected] or call (936) 206-5500.
We will not threaten you for reporting something in good faith. Give us a reasonable chance to fix it before you publish it, and we will tell you when it is done and credit you if you want the credit.
We are not going to put a compliance badge on this page that we cannot stand behind. We hold no certification we have not earned, and we are not claiming one here. If a claim on this page matters to your decision, ask us to put it in the agreement — that is where a promise is worth something.