Your accounts, your data, your call.
How Orbitmate protects the LinkedIn accounts you connect and the data you bring, stated plainly, with nothing we can’t back up.
Controls that keep every sender at a human pace.
Every sender runs within its own limits, and nothing goes out without a person approving it.
Every action is approved
Connection requests, messages, comments and reactions all wait in the approval queue until a person approves, edits or rejects them. This can’t be switched off.
Daily caps per sender
Each LinkedIn account has its own daily limits: 15 connection requests, 40 messages, 10 comments and 30 reactions by default. Connection and message caps can be changed per sender.
Warm-up for new accounts
A newly connected sender starts at 20% of its caps and ramps up to full over 14 days.
Checkpoint cut-back
If LinkedIn challenges an account, its caps drop to 25% for three days while the account settles.
Working hours
Each sender has working hours in its own time zone. An action only goes out when both the sender’s hours and the campaign’s schedule are open.
One proxy and profile per sender
Every sender runs in the cloud with its own dedicated proxy and browser profile, so accounts are never mixed. Deleting a sender purges its profile.
Encrypted, separated and kept only as long as needed.
Each organization’s contacts, campaigns and inbox stay in its own workspace.
Encrypted where it matters most
Inbox messages, provider API keys, LinkedIn passwords, two-step verification secrets and proxy passwords are encrypted in the application with AES-256-GCM. Inbox content uses a separate key per record.
LinkedIn sessions
Session data is stored on encrypted storage using a dedicated KMS key, and is only ever used by the sender it belongs to.
Hosting and backups
The product runs on AWS in us-east-1. The database sits on encrypted disks, with daily snapshots and a nightly encrypted backup to S3. Secrets live in AWS SSM Parameter Store.
Retention
Inbox message content is deleted after 365 days, as are uploaded import files. Raw data returned by enrichment providers is cleared after its retention window. See privacy.
Access control
Owner, Admin and Member roles plus custom roles with fine-grained permissions. Each sender has its own owner, editor and viewer team.
Sign-in and audit
Email and password with optional TOTP two-factor authentication. Active sessions can be reviewed and revoked, and an audit log records who did what, with CSV export.
Found a vulnerability?
How to report
Email security@orbitmate.ai with a description, steps to reproduce and the impact you observed. We will acknowledge your report and keep you updated while we fix it.
Please
- Give us reasonable time to fix an issue before disclosing it.
- Don’t access, change or delete other customers’ data.
- Don’t run denial-of-service tests or send outreach from accounts you don’t own.
Security questions.
Can Orbitmate send without my approval?
Will using Orbitmate get my LinkedIn account restricted?
Which AI providers see my data?
Do you support SSO?
How do I delete our data?
Do you hold any security certifications?
Need a security review or a questionnaire filled in? Contact us.
Your next conversation starts here.
Connect a LinkedIn account, add the people you want to reach, and approve your first drafts today.