Orbit

Orbit for Business

Run your team's tasks on your own machines. Seats, roles, and live sync - hosted by you, encrypted end to end, never on our servers.

How it works

An Orbit organization has no cloud behind it. Your desktop is the server, your people's devices are the clients, and everything in between is sealed.

Your desktop is the host

Sign in with your organization key on your Windows or Linux desktop. That machine holds the org's encrypted database - there is no cloud copy anywhere.

You create seats

One seat per person, with a name and a role. Each seat covers 2 desktops and 1 mobile device for that person.

They join with a link

Every seat gets a one-tap invite link (or a claim code / QR). The link opens a guided setup that downloads Orbit and walks them in.

Everything syncs sealed

Devices talk to your host directly, with every request body sealed with AES-256-GCM. Each person only ever receives the items they are allowed to see.

Your organization's data lives on your machines and your people's devices - nowhere else. If remote members use the optional relay, it only ever forwards sealed data it cannot read and stores nothing. WrenchyProductions only ever sees the licence key.

Everything a small team needs

Seats & devices

Each seat is one person with 2 desktop + 1 mobile device slots. Their first device activates instantly; extra devices wait in your approval queue.

Roles

Manager, director, and staff. Managers run the org; directors and staff see and work on what is theirs - never the whole database.

Task assignment

Assign a task to a person, a team, everyone, or leave it unassigned - unassigned org tasks stay visible to managers only.

Project sharing

Share a project with specific people or teams via "Shared with". Sharing widens visibility: everything inside the project comes with it.

Idea visibility

Each org idea has a visibility floor: staff and up, directors and up, or managers only. People below the floor never receive it.

Teams

Group people into teams, then assign tasks or share projects with the whole team at once. Membership changes apply on the next sync.

Remote access, your call

Out of the box the org is LAN-only. Flip a toggle for encrypted relay access from anywhere, or port-forward for a direct connection with instant updates.

Instant revocation

Revoke a seat and every one of its devices stops syncing and purges its local copy of the org data - even devices that are off-network purge on their next contact.

Set up in minutes

  1. 1

    Get your organization key

    Tell us your team size and we set up a key sized to your seats. One key covers the whole organization.

  2. 2

    Sign in as the host

    Open Orbit on your desktop, click "Organization login" in the bottom-right of the activation screen, paste your key, and fill in your profile. Your machine is now the org host.

  3. 3

    Create a seat per person

    In Settings, open the Organization panel and add a seat with a name and role. Hit "Copy invite link" and send it over - the link opens a guided page that auto-downloads Orbit and walks them through joining.

  4. 4

    Approve extra devices

    Each person's first device activates instantly. If they add a second desktop or a phone, it appears in your approval queue until you allow it.

  5. 5

    Optional: enable remote access

    Working from one office network? You are done. Got remote people? Turn on external access in the Remote access card - it is off by default.

Every setting, explained

The full reference for what managers and members control, exactly as it appears in the app.

Remote access (manager)

By default an Orbit organization is LAN-only: nothing about it is reachable from outside your network. Three toggles control everything beyond that.

Allow external access
Lets seat devices join and sync from outside your network through the end-to-end encrypted relay. The relay only ever forwards sealed data it cannot read and stores nothing. Off by default.
Live updates for external members
When on, external devices are nudged the moment something changes so they pull immediately. When off, they simply pick up changes whenever they sync (on a schedule or with Sync now).
Direct connection
For instant updates without the relay: forward a port on your router (Orbit's default is 7421), enter your public address, and seat devices connect straight to your host. Invite links created afterwards carry the address automatically, with a LAN fallback for people in the office.

Seat management (manager)

Create a seat
A name plus a role (manager, director, or staff). Orbit mints a one-time claim code shown as text, a QR code, and a shareable invite link.
Invite link
An orbit-reminders.com/join link with the seat's claim sealed in the URL fragment - browsers never send fragments to any server, so the code stays between you and the new member. The page auto-downloads Orbit and shows numbered setup steps.
Transfer
Hands a seat to a new person: they keep the seat's tasks and history, and Orbit mints a fresh claim code. Transfer is also your kill-switch if an invite link leaks - the old code dies instantly.
Revoke
Removes the seat. All of its devices stop syncing and purge their local copy of the org data.
Device approval
Extra devices beyond a seat's first one land in a pending queue. Approve or reject each device individually.

Workspace controls (manager)

Teams
Create teams and toggle members in or out. Teams can be assignees on tasks and grantees on projects.
Project "Shared with"
Grant a project to specific people or teams. Everyone granted sees the project and everything in it, on top of whatever their assignments already show them.
Task assignee
Every org task has an assignee field: a person, a team, everyone, or unassigned (managers only). Assignment decides who receives the task on sync.
Idea visibility
Org ideas carry a role floor - staff and up, directors and up, or managers only.
Your profile
Your display name and details as your organization sees them. Visible to your seats - never to us.

The employee side

Personal / Organization toggle
One click in the sidebar switches between their private personal workspace and the org workspace. Hovering the org side shows the full organization name. The two never mix.
Sync now & status
Employees see when they last synced and how they are connected (direct or relay), and can trigger a sync on demand.
Host address
If your public address changes, employees can update the host address on their end without re-joining.
Leave organization
Any member can leave. Leaving stops sync and removes the org's data from their device; their personal workspace is untouched.

Roles & permissions

Managers run the organization. Directors and staff work inside the slice that is theirs - directors simply clear a higher idea-visibility floor than staff.

ManagerDirector / Staff
SeesEvery org task, project, category, and idea.Items assigned to them, their teams, or everyone; projects shared with them; ideas at or below their role floor.
Creates & deletes org itemsYes - tasks, projects, categories, ideas, teams.No. Org items are created by managers.
EditsEverything.The content of what they see: title, notes, due dates, subtasks, reminders, attachments, tags, and completion.
Assignment & visibilityAssigns tasks, shares projects, sets idea visibility.Cannot reassign items or change who sees what.
Org settingsSeats, devices, teams, remote access.Their own device and sync settings only.
Personal workspacePrivate. Invisible to the org.Private. Invisible to the org - including managers.

Security & privacy

  • Every database is encrypted at rest with SQLCipher - on the host and on every seat device.
  • Sync bodies are sealed with AES-256-GCM. Decrypting is the authentication: there are no bearer tokens or passwords on the wire to steal.
  • Seat identities are Ed25519-signed by your organization's own key, minted on your host.
  • Private by default: the org is LAN-only until you switch on external access.
  • The optional relay is blind - it forwards sealed data it cannot read and stores nothing.
  • Revocation is authenticated and final: a revoked device proves the order came from your host, then purges its copy.
  • Your organization's data never touches our servers. We only ever see the licence key.

Get your organization key

Organizations are priced per seat, with volume discounts against the standard licence. One key covers every seat's devices - 2 desktops and 1 mobile per person - and personal-use mode is bundled for everyone.

Tell us your team size - we set up your key and send a secure checkout link.

Business questions

Do employees need their own licence?

No. One organization key covers every seat - each person gets 2 desktop and 1 mobile device slots under it, with nothing extra to buy or activate.

What happens if the host computer is off?

Everyone keeps working normally - Orbit is local-first, so each device has its own encrypted copy of what it is allowed to see. Changes queue up and sync automatically the next time the host is reachable.

Can people work from home?

Yes. Turn on external access and remote devices sync through the end-to-end encrypted relay. For instant updates you can also forward a port and use a direct connection to your host.

Can employees see my personal tasks?

Never. Personal and organization are two separate workspaces, and the separation cuts both ways: the org never receives personal items, and personal devices never receive org items they were not granted.

What does WrenchyProductions see?

Only the licence key when it is activated. Your organization's tasks, people, and projects live on your machines; if the relay is used it only ever carries sealed data it cannot read and stores nothing.

What happens when someone leaves the company?

Revoke their seat, or transfer it to their replacement (the new person keeps the seat's tasks and history). Either way the old devices stop syncing and purge the org's data - even off-network devices purge on their next contact.

Which platforms are supported?

The host runs on Windows and Linux desktop. Seat members can use Windows, Linux, and Android.

Want Orbit for yourself first? See the personal edition