Legal

Security

How Opsync protects your data: encryption, row-level tenant isolation, access controls and responsible disclosure.

1. Our Commitment

Security is fundamental to Opsync. We implement technical and organisational measures designed to protect your data against unauthorised access, disclosure, alteration, or loss.

2. Encryption

All data transmitted between your browser and Opsync is protected using TLS 1.2+ (HTTPS). Data stored in our database is encrypted at rest using AES-256 through Supabase's managed cloud infrastructure.

3. Access Controls & Multi-Tenancy

Row-Level Security (RLS) policies enforced at the PostgreSQL database level ensure each organisation's data is strictly isolated — no query can access another tenant's data. Role-based access control (Admin, Manager, User) within your organisation limits what each team member can view or modify. All access is logged in an immutable audit trail.

4. Infrastructure Security

Our infrastructure runs on Supabase (database, authentication, file storage) and Vercel (application hosting). Both providers maintain SOC 2 Type II compliance. Supabase performs daily automated database backups retained for a minimum of 7 days.

5. Responsible Disclosure

If you discover a security vulnerability in Opsync, please disclose it responsibly by emailing hello@opsync.digital with subject 'Security Disclosure'. Include a description of the issue and steps to reproduce. We request that you do not publicly disclose the issue until we have had 30 days to investigate and remediate. We acknowledge all valid security reports.

6. Incident Response

In the event of a confirmed data breach affecting your personal data, we will notify affected customers within 72 hours of becoming aware, as required by applicable law. Notification will describe the nature of the breach, data categories affected, and steps taken to mitigate harm.

7. Security Contact

Security disclosures and concerns: hello@opsync.digital — please include 'Security Disclosure' in the subject line.