Skip to main content
Trust

Security.

What is in place today, and what is not yet. We would rather you read an honest list than a certified-looking one.

HostingUnited States
PaymentsStripe, we never hold card numbers
Reportssecurity@operanttechnologies.com

Getting in

One account per personNo shared logins. Accounts are issued by company, gated by seat, and removed when someone leaves.
Two-step sign-inAuthenticator codes with recovery codes on every account, and an owner can require it for the whole company. A device can be trusted for 30 days; the password is always required.
Sessions you can see and endEvery signed-in device is listed in Settings and can be signed out from there. All sessions are revoked when a password is reset or the account email changes.
One-time links, used onceEmail confirmation and sign-in links work exactly once and expire. A reused link gets a dead end, not a session.
PasskeysThe plumbing is in place; enrolment ships shortly. Touch ID or Windows Hello instead of password and code.
Single sign-onNot yet. SAML and SCIM are on the list for companies that need them.

Your data

Encrypted in transitTLS on every connection. No plain HTTP anywhere in the product.
Encrypted at restDatabases and file storage are encrypted on disk by our hosting providers.
Separated by companyEvery record carries its company. Queries filter on it, and database row-level policies back the application checks.
Private file linksScreenshots and uploads are served through an authenticated check of your company, not from public URLs.
Mailbox tokens encryptedWhere a company connects a mailbox, the access tokens are envelope-encrypted with a key we can rotate.
Export on requestAccount owners can request a full export at any time, in an open format.

How we run it

Continuous backupsManaged Postgres with point-in-time restore on a rolling window. Restores have been exercised.
Least privilege, loggedTwo founders, no one else. Access to customer accounts for support is tagged in the audit log the customer can see.
Audit trailEvery meaningful account action is recorded: sign-ins, settings changes, people added or removed, support activity.
Rate limitingSign-in attempts, email changes and public forms are throttled to blunt credential stuffing and abuse.
Automated dependency alertsNot yet wired. Dependencies are updated by hand today; automated vulnerability alerts are planned.
Twenty-four hour monitoringUptime checks page us around the clock, but humans respond during working hours, 7–4 MT.

Payments

Billing not live yetPilots are free and nothing is charged without a signed order. When billing goes live it will run through Stripe, and card details will never touch our servers.

Not in place yet

SOC 2We have not been audited. When that changes, the report will be available under NDA.
Penetration testNo third-party test has been done yet. Planned before general availability.
Status pageNot up yet. Incidents and planned maintenance are announced by email to account owners until it is.
Found something

Send it to security@operanttechnologies.com and we will confirm within one business day. We will not pursue anyone who reports a genuine issue in good faith.