Trust and security

Security

How your compliance dashboard and everything else we hold is protected, who can see it, and what we promise if something goes wrong.

Last updated: 5 October 2026

Our Commitment

Your compliance dashboard holds the names of your staff, when each signed your AI policy, and the incidents you have logged. This page sets out exactly how that is protected, who can see it, and what we promise if something goes wrong. Every statement here describes something our systems do today.

Your Compliance Dashboard

  • Two keys to open it: your private link finds the dashboard, and a six-digit code emailed to the address you bought with opens it. A forwarded link on its own opens nothing.
  • One-time codes: each code works once, for 15 minutes, and stops working after 5 wrong tries. A new code can be sent at most once a minute. We keep only a scrambled copy of a code, never the code itself.
  • Codes only when you ask: a code is sent when you press the button, never when the link is opened, so the security scanners that open every link in a business's email cannot trigger one.
  • Remembered devices: a browser that has opened your dashboard is remembered for 30 days, so you are not asked for a code on every visit.
  • A new link in one click: if your link ever goes somewhere it should not, one button gives you a new private link and every old one stops working.
  • A full history: every change to your dashboard is recorded with the date and how it was made: on the dashboard, by email, or by us.
  • Kept away from AI models: staff names, training dates and incident notes are never sent to an AI model.
  • Out of search engines: dashboard pages tell search engines not to index them.

Who Holds Your Data, and on What Terms

  • A written contract: for what you enter on your dashboard, you are the controller and we are your processor. Section 6A of our Terms of Service is the contract Article 28 of the UK GDPR requires between us, and it applies in the same way under the EU GDPR.
  • Who can see it: only people working for Ops Intel who need to in order to provide the service, each bound by a duty of confidentiality.
  • If something goes wrong: we tell you within 48 hours of becoming aware of a breach affecting your dashboard data, with what we know, so you can meet your own duty to report it.
  • When you leave: if your cover ends and is not renewed, everything you entered is deleted 30 days later, unless the law requires us to keep it. You can download your documents at any time before then.

Infrastructure

  • Hosting: Ops Intel runs on Railway, whose platform is independently audited to SOC 2 Type II.
  • Where your data is kept: in Railway's United States data centre. Transfers from the UK and EU are covered by the safeguards in section 11 of our Privacy Policy.
  • Encryption in transit: every connection to the site is encrypted (HTTPS), and browsers are told to refuse any unencrypted connection to us for a year.
  • Encryption at rest: stored data is encrypted by our hosting provider at the storage level.
  • Backups: the database is backed up automatically every day and every week by our hosting provider.
  • Database: PostgreSQL on Railway's private network. The one route to it from outside is password-protected and used only for our own maintenance.

Application Security

  • Authentication: Passwords are hashed using Django's PBKDF2-SHA256 algorithm. We support email verification on signup.
  • Session security: HTTPS-only secure cookies with HttpOnly and SameSite=Lax flags.
  • CSRF protection: All state-changing requests require a valid CSRF token.
  • Multi-tenancy: All data is isolated by tenant at the database query level — it is architecturally impossible for one tenant's data to be accessed by another.
  • Role-based access control: Four roles (Owner, Admin, Manager, Viewer) with enforced permission checks on every endpoint.
  • Secret management: API keys and secrets are stored as environment variables and never committed to source code.

Questions IT Teams and Insurers Ask

  • Is Ops Intel SOC 2 or ISO 27001 certified? Ops Intel itself is not. Our hosting provider is audited to SOC 2 Type II, and we keep what we hold to what the dashboard needs. The frameworks we write are aligned with ISO/IEC 42001 and the NIST AI Risk Management Framework; aligned, not certified.
  • Do you support single sign-on? Not today. The dashboard opens with your private link and a one-time code, so there is no password to steal, reuse or forget.
  • Can we see who changed what, and when? Yes. The History panel on your dashboard records every change with its date and how it was made.
  • Is our data used to train AI? Staff names, training dates and incident notes are never sent to an AI model at all. Your answers to our questions are sent to our AI provider, Anthropic, to write your documents.
  • Where is our data stored? In the United States, with Railway. See Infrastructure above.

Payment Security

We do not store payment card data. All payment processing is handled by Stripe, which is PCI DSS Level 1 certified. We store only non-sensitive billing metadata (last 4 digits, expiry month/year).

Third-Party Sub-processors

We use a small number of vetted sub-processors, each under a data processing agreement. This list matches the one in our Privacy Policy:

  • Railway (cloud hosting — all platform data)
  • Stripe (payments)
  • Resend (email delivery)
  • Anthropic (AI features — message content is processed but not stored)
  • Make.com (automation workflows)
  • Hugging Face (turning chat messages into a numeric form so our AI receptionist can look up the right answer)
  • Google (Gemini AI research and company lookup; PageSpeed website scoring)
  • PostHog (website analytics, session replay with input masking, error reporting, and product usage analytics — no customer content, EU infrastructure)
  • Cal.com (call booking)
  • Google (Preferred Sources button on our blog articles)

Responsible Disclosure

If you believe you have found a security vulnerability in Ops Intel, please report it responsibly:

  • Email: hello@opsintel.io with subject line "Security Disclosure"
  • Include a description of the vulnerability and steps to reproduce it
  • Do not publicly disclose the issue until we have had a reasonable opportunity to investigate and remediate

We will acknowledge your report within 3 business days and aim to resolve confirmed vulnerabilities within 30 days. We do not currently offer a bug bounty programme, but we sincerely appreciate responsible disclosures.

Incident Response

In the event of a data breach affecting your personal data, we will notify affected users and the Information Commissioner's Office (ICO) within 72 hours of becoming aware, in accordance with UK GDPR Article 33.

For data you have entered on your compliance dashboard, where we are your processor, we tell you within 48 hours of becoming aware, as section 6A of our Terms of Service sets out.

Questions

For security enquiries, contact us at hello@opsintel.io. What we provide, our service levels and how you leave are set out in our service definition.

Call Now See prices