Orbit hardened staging. Server modules use V8 cached code bound to bundled Node; loaders remain readable. Browser UI remains readable. This raises casual inspection cost; determined reverse engineering is possible.
Launcher verifies an RSA-SHA256 signed file manifest. The embedded verification key and launcher can themselves be patched; this is not Authenticode or a trusted Windows publisher signature. Do not call this unbreakable.
No debugger detection, machine-code bans, or remote licensing. Mutable user data is excluded from integrity checks. Credentials are generated locally at first launch.
Third-party license review and fresh-machine end-to-end verification remain required before public download.