Authenticate
TOTP two-factor or OIDC or SAML SSO proves who's knocking. SCIM provisions and deactivates admins straight from your IdP.
OpsIQ protects the complete operating surface: people and identities, application code, secrets and customer data, APIs and webhooks, connector packages, AI actions, support channels and incident evidence. Sensitive operations are scoped, authorised, verified and made accountable from request to result.
sha256=8a41…b90f · nonce accepted
✓ timestamp fresh · replay rejected
Only the right people get in, and high-risk actions verify them again. TOTP and recovery codes protect local sign-in; OIDC or SAML connects enterprise identity; SCIM governs joiners and leavers. Password policy, breached-password screening, IP and account lockouts, new-device alerts, device revocation and step-up confirmation protect the space between first login and a sensitive change.
TOTP two-factor or OIDC or SAML SSO proves who's knocking. SCIM provisions and deactivates admins straight from your IdP.
Owner / admin / support roles plus per-page grants mean each person reaches exactly what their job needs, nothing more.
Security events and registered human or AI actions carry actor, IP, time and result through a tamper-evident audit chain.
Every request moves through the same security choreography: prove identity, prove authority, sign the path, seal the data. The result is a platform that feels fast without ever becoming casual about access.
TOTP two-factor, OIDC or SAML SSO and SCIM joiner/leaver flows verify who is entering before any admin surface opens.
Owner, admin, support and page-level grants keep every teammate inside the exact boundary their role allows.
Webhook traffic and API calls are scoped, HMAC-verified, replay-protected, rate-limited and tied to one workspace.
Security events and registered AI or admin actions land in a tamper-evident, workspace-scoped audit chain.
The firewall classified the source, crossed the failed-login threshold and added the address to the active block list.
Registered AI actions, admin changes and webhook deliveries can be recorded with actor, IP, action, result and approval state.
HMAC signatures, nonces, timestamps, scoped keys and optional IP allowlists stop forged or replayed traffic early.
Failed-login lockout, IP and CIDR blocking, bot scoring, rate limits and account-takeover signals keep pressure off the core.
Workspace and site identifiers are enforced through access checks, API-key scopes, connector ownership and audit ownership, keeping one customer request from being resolved inside another customer's context.
TOTP, recovery codes, OIDC and SAML SSO, SCIM provisioning, password policy, breached-password screening, new-device review and step-up verification.
Owner, admin, support and granular grants meet action scopes, confirmation policies and workspace boundaries before a protected operation proceeds.
Sensitive values use authenticated encryption with installation-bound key material and unique nonces. Interfaces redact stored values and support rotation.
OpsIQ's AI cannot invent operations. Every action it can take is a registered contract with declared scope, roles and parameters, and anything off-contract is rejected at the brain layer before it reaches an endpoint. Risky writes require explicit human confirmation. You choose the provider or self-hosted deployment; data handling follows that selected provider and deployment policy, while OpsIQ does not use workspace content to train its own models.
action.refund_invoice · workspace/acme-prod
A full OpsIQ backup can move or restore the installation without turning its most sensitive material into an ordinary archive. The worker streams bounded chunks into a sealed .opsiqx container, then restore verifies the file before any import is applied.
The archive carries the protected data, files, configuration and secret material needed for a complete cross-host recovery. A passphrase-derived key seals it; authenticated chunks expose alteration; optional origin signing proves where it came from.
header authenticated · archive metadata bound
✓chunk stream valid · final tag present
✓origin verified · Ed25519 signature accepted
→restore is still preflight only · import not applied
A complete control surface for identity, code, data, APIs, connectors, AI, customer channels and incident response. Built for a serious enterprise review, not a checklist of login features.
Honest status: what is live, what is aligned, and what is on the roadmap. No borrowed badges, no certification claims we do not hold.
Know who's knocking, release a locked teammate in one click, and watch the platform guard its own health, every move logged.
OpsIQ doesn't just count bad logins; it tells you what kind of address is hitting you. Each IP is classified as residential, shared, datacenter or internal, then given a 0–100 threat score from bot and takeover signals on the visitor journey. Datacenter ranges hammering your login form look very different from a customer on home broadband, and your lockout thresholds can treat them differently.
When a teammate gets locked out, you release them in one click, with no waiting for a timer. Sweep active failed-login counters in bulk after an incident, search the full failed-login history to investigate, and bulk-delete stale records once it's resolved. Every release, reset and deletion is itself written to the audit log, so the cleanup is as accountable as the breach.
Beyond the perimeter, OpsIQ guards its own integrity. A signed license check keeps the install genuine, built-in health diagnostics surface a live snapshot of the platform's vital signs, and front-end JavaScript errors are captured server-side so a broken release shows up in your dashboard instead of silently failing on a customer's screen.
The opt-in analyst turns identity, abuse and audit signals into a defensible incident narrative, without entering the request path or taking irreversible action.
Deterministic scoring remains the first line of defence. The model is asked only when interpretation helps: an ambiguous IP, a fresh incident or a daily posture brief. Related entities batch into one review, verdicts are cached, and a hard monthly budget lives in AI Config. If that budget is reached, blocking, lockouts and alerts continue under deterministic policy.
Blocked IP and failed-login rows show benign, suspicious or hostile confidence. Explain opens the facts used, the reason, and one-click Block or Release. Cached reviews stay free.
Related events become one story: login waves, URL scans and auto-block bursts. Each incident gets a plain-English timeline, one next move, and ongoing attacks fold into the same case.
One morning recap compares yesterday with your baseline, lists new blocks and incidents, then highlights the single action worth doing today. Quiet days return all clear at zero tokens.
A Monday checklist surfaces admins without 2FA, loose lockout thresholds and disabled alerts. Every item includes severity, effort, and the exact fix to approve or assign.
Ask why an IP was blocked, what changed overnight, or what to harden first. Answers come from live security state; deep server work routes to admin engineering, never guessed.
Proposes reversible block rules with Approve or Dismiss cards and live hit counters. Autopilot stays opt-in, time-limited, capped, undoable, and never targets shared/mobile ranges.
The analyst suggests, clusters and (only with autopilot on) applies reversible blocks. It cannot delete data, change settings, touch the audit ledger or make a permanent ban; each registered analyst action is written to the tamper-evident audit chain.
Every capability, grouped. ★ marks a stand-out.
| Feature | What it does |
|---|---|
| Authentication | |
| Two-factor (TOTP) | Per-admin RFC-6238 two-factor for Google Authenticator, 1Password, Authy or any compatible app. |
| Single-use recovery codes | Regenerable backup codes so a lost device never locks you out for good. |
| OIDC single sign-on | Connect an eligible enterprise identity provider and preserve password access where policy permits. |
| SAML 2.0 single sign-on | Support SAML-speaking identity providers with domain policy and certificate configuration. |
| SCIM provisioning | Automatic admin create and deactivate from your IdP; every change logged. |
| Password policy | Set minimum requirements for newly created or changed passwords. |
| Breached-password screening | Optional Have I Been Pwned screening uses k-anonymity: only a short hash prefix leaves the server, never the password. |
| Account lockout | Protect an account when credential stuffing rotates across source IPs. |
| Step-up verification | Require fresh password confirmation before dangerous actions, with a short-lived verification window. |
| New-device alerts & revocation | Email and in-app alerts surface unfamiliar sign-ins so authorised admins can review and revoke devices. |
| reCAPTCHA on login | Optional bot challenge on the sign-in form to slow automated attacks. |
| Hardening | |
| Failed-login lockout ★ | Rolling failure counters trip an automatic IP lockout once the threshold is crossed. |
| IP & CIDR blocking ★ | Block a single address or a whole range by hand; bans propagate across a session. |
| IP classification ★ NEW | Each address tagged residential, shared, datacenter or internal on every event. |
| Threat scoring | 0–100 bot and account-takeover score; anything ≥50 is highlighted. |
| Rate limiting | Sensitive and public request surfaces can be throttled against brute force and abuse. |
| Content Security Policy | Report-only and enforce modes help control scripts, frames, connections and browser-side injection risk. |
| CSRF validation | State-changing browser requests use token and header validation. |
| Upload quarantine | Untrusted files are isolated and checked before they join a trusted workflow. |
| Portal abuse controls | Honeypot, rate limits, disposable-email blocking and reCAPTCHA or Turnstile can protect public support submissions. |
| Code & connector security | |
| Custom-code governance ★ | Custom JavaScript revisions can be staged, separately approved or rejected, disabled and rolled back. |
| Emergency disable | Disable governed custom code without deleting its revision history or losing the rollback path. |
| Package hashes & signatures | Connector archives verify file integrity and package signatures before installation. |
| Ed25519 provenance | Prefer cryptographic proof of package origin when a connector supplies it. |
| Static safety scan | Uploaded archives are inspected and unsafe executable patterns are rejected before files are committed. |
| Contract conformance | Manifest, handlers, settings, documentation and declared capabilities pass a shared registry gate. |
| Runtime policy | Least-privilege scopes, confirmation, dry runs, idempotency contracts and audit records govern connector execution. |
| Messaging & abuse security | |
| Shared block decisions | Email, domain and IP blocks protect the applicable support surfaces from one policy layer. |
| Known-customer guard | Real customer ticket history avoids being screened as an unknown spam sender. |
| AI Spam Detector ★ | Local heuristics handle clear cases first; the model reviews ambiguous new-sender messages only when needed. |
| Advisory or autonomous mode | Choose whether suspicious messages are suggested for review or moved under the configured policy. |
| Restorable spam isolation | Suspected spam stays readable and reviewable so operators can restore a false positive. |
| Provider fail-open policy | If optional model review is unavailable, delivery is not silently discarded. |
| Authorization | |
| Role-based access control | Owner, admin and support roles so each person sees only what their job needs. |
| Per-page permission grants NEW | Grant or revoke individual admin pages per teammate for fine-grained access. |
| Confirmation policies | Per-action gating that forces an explicit confirm step on sensitive operations. |
| Data protection | |
| Workspace-scoped access ★ | Workspace and site identifiers, key scopes, connector ownership and audit ownership travel with protected operations. |
| Authenticated secret storage | Sensitive integration values use authenticated encryption with installation-bound key material and a unique nonce. |
| Secret redaction & rotation | Stored values are masked in interfaces and can be replaced without exposing the saved plaintext. |
| Protected application keys | Installation secrets are kept outside public web paths and are not returned through ordinary API responses. |
| Backup & recovery security | |
Sealed .opsiqx archive ★ | Package a full installation recovery set inside an OpsIQ-specific encrypted container. |
| Argon2id key derivation | A unique salt and memory-hard password hashing derive the per-archive stream key. |
| Authenticated secretstream | XChaCha20-Poly1305 authenticates metadata and every bounded chunk while keeping peak memory controlled. |
| Optional Ed25519 provenance | A detached signature can prove the sealed file originated from the signing installation. |
| Truncation-fatal restore | Wrong passphrase, altered bytes or a missing final tag remove partial output and stop import. |
| Worker-driven backup jobs | Large backups progress in bounded slices and expose status instead of occupying one long web request. |
| API security | |
| Signed webhooks ★ | HMAC-SHA256 over the raw body with timestamp and nonce replay protection, both directions. |
| Scoped API keys | Workspace-locked keys in All, Read-only or Restricted permission modes. |
| IP allowlist on keys | Restrict a key to specific IPs or CIDR ranges so a leaked key is still useless elsewhere. |
| Key rotation & revocation | Rotate or revoke any key instantly; secret keys are never returned again after creation. |
| Per-hour rate limits | Each key carries its own request budget to contain abuse. |
| Audit | |
| Tamper-evident audit chain ★ | Security and registered action records can carry actor, role, IP, time, action and result in a verifiable hash chain. |
| Chain verification & checkpoints | Verify ledger continuity, create integrity checkpoints and account for authorised redactions. |
| CSV / JSON export | Hand auditors the whole trail in a portable format. |
| Filtering | Slice the log by action, actor, date or risk to find exactly what you need. |
| Security events | Sign-ins, 2FA, permission and SCIM changes are all recorded as events. |
| Failed-login journey timeline ★ | Every attempt against an account replayed as its own reviewable journey. |
| Lockout & counter monitoring NEW | See every live failed-login counter and active lockout at a glance. |
| Failed-login history search NEW | Search the full history of login attempts to investigate an incident. |
| Incident response | |
| Manual lockout release NEW | Clear a locked admin or IP in one click without waiting for a timer. |
| Bulk counter reset NEW | Sweep all active failed-login counters clear after an incident. |
| Bulk history deletion NEW | Purge resolved failed-login records in bulk; the deletion itself is logged. |
| Installation self-IP guard ★ | The installation's own IPv4 and IPv6 are excluded from attack classification, scan detection and automatic block waves. |
| System protection | |
| License integrity | Signed validation keeps the install genuine and tamper-evident. |
| Health diagnostics NEW | A live snapshot of the platform's vital signs, on demand. |
| JavaScript error capture NEW | Front-end errors are logged server-side instead of silently failing on a customer's screen. |
| Outbound request guard | Remote calls are constrained to reduce SSRF and unsafe destination risk. |
| Connector security sync | Security block decisions can be synchronised with compatible connected systems. |
| AI safety | |
| Action contracts ★ | The AI can only invoke registered operations with declared scope, roles and parameters. |
| No off-contract actions | Unknown operations are rejected at the brain layer before they reach an endpoint. |
| Human approval on risky writes | Sensitive actions always require an explicit human confirmation. |
| Registered AI actions logged ★ | Action execution, result and approval evidence can be written to the audit trail. |
| Provider policy visibility | Data handling follows the AI provider and deployment selected by the workspace. |
| Compliance & admin | |
| Data residency & retention | Cloud location and retention follow the workspace service configuration; self-hosted data remains in the chosen deployment. |
| Owner-only audit access | The full AI history audit log is restricted to the workspace owner. |
| Privacy operations | DPA support, DSAR export/delete tooling, consent records and configurable retention workflows. |
| Admin user management NEW | Invite, role, deactivate and audit every admin from one console. |
| Department management NEW | Organise teams into departments with their own access and routing. |
/.well-known/security.txt, or open the contact page and choose the security route. Current security evidence can be discussed during a vendor review..opsiqx archive uses Argon2id key derivation and XChaCha20-Poly1305 authenticated streaming. Optional Ed25519 provenance verifies origin, and an altered, wrongly unlocked or truncated archive is rejected before import applies anything. Backup jobs run in bounded worker slices so a large installation does not depend on one long web request.