Security & Data Handling
This page summarizes the security model of the ORION Data API for security reviewers evaluating an integration.
What the API exposes
Section titled “What the API exposes”The API serves composite resilience metrics only:
- The QR Score (0–100) and its grade
- The four pillar scores (0–100 each)
- The dated history of the composite score
It does not expose raw findings, vulnerability data, asset inventories, device details, network topology, or security control output. The score is designed to be shareable precisely because it quantifies resilience without describing the environment that produced it.
Authentication and authorization
Section titled “Authentication and authorization”- Access requires a per-authorization credential pair (Client ID + API key), created by the data owner in their ORION environment (see Authentication)
- Each credential is bound to exactly one organization and limited to the data scopes the organization selected
- The API key is displayed exactly once at creation. Overspace stores only a one-way keyed hash; raw keys cannot be recovered from Overspace systems
- The data owner can revoke a credential at any time, effective immediately; authorizations can also carry an expiration date
Transport security
Section titled “Transport security”The API is served exclusively over HTTPS (TLS 1.2 or higher). Plaintext requests are not accepted.
Tenant isolation
Section titled “Tenant isolation”Every customer runs in a dedicated tenant environment with its own isolated data store. Each customer controls authorization generation and revocation from within their own tenant environment: credentials are created, scoped, and revoked there, not by Overspace on the customer’s behalf. The API resolves each request to the single tenant the credential is bound to; there is no shared data plane through which one customer’s data could reach another customer’s credential.
Edge protections
Section titled “Edge protections”All traffic passes through a web application firewall and rate limiting before reaching the API.
Reporting a vulnerability
Section titled “Reporting a vulnerability”If you believe you’ve found a security issue in the ORION Data API or any Overspace system, email security@overspacehq.com. Include enough detail to reproduce the issue; we’ll acknowledge receipt and keep you informed as we investigate.
