Trust center

Security, compliance and uptime โ€” in one place.

Where your data lives, how it's encrypted, who can access it, what the AI is allowed to read, and the audit trail behind every operation. No marketing fog โ€” just the questions your security team will ask, with real answers.

99.95%cloud uptime SLA
AES-256at rest ยท TLS 1.3 in transit
HMACSHA-256 on every API call
100%of AI turns logged
Security at every layer

How we protect your data and your customers'.

๐Ÿ”’ Encryption

AES-256 at rest. TLS 1.3 in transit. Per-tenant keys on cloud.

Every byte you store with us is encrypted with AES-256 using per-tenant keys. Every byte we send across the wire uses TLS 1.3. API secrets and webhook signing keys are sealed with envelope encryption โ€” never logged in plaintext anywhere.

๐Ÿ”‘ Access control

Role-based, scoped, optional SSO.

Owner, admin, support & custom roles. 2FA on every account. SSO available on Business plans.

๐Ÿช Signed integrations

HMAC-SHA256 on every webhook.

Replay protection via timestamp + nonce. Idempotency keys on all write APIs. Per-connector secret rotation.

๐Ÿง  AI safety

The AI cannot invent operations.

Every call goes through an action contract with role gates and confirmation policies. Risky operations require explicit human approval โ€” always.

๐Ÿ“œ Audit trail

Owner-only. Complete. Exportable.

Every admin action, every AI turn, every webhook delivery โ€” logged with actor, timestamp, IP, duration. CSV export.

๐Ÿ›ก๏ธ Operational hardening

Built for hostile internet.

IP firewall & CIDR blocklists, bot/threat scoring on visitor logs, rate limiting, replay-protected gateway events.

Compliance posture

Built for serious compliance reviews.

Our cloud platform is engineered with the controls security teams expect. Self-hosted customers retain full control of their data residency, retention and audit policy.

๐Ÿ‡ช๐Ÿ‡บ

GDPR-aligned

Data subject access, deletion & export workflows built into the account portal.

๐Ÿช

Cookie consent

Built-in consent banner with regional defaults & per-cookie opt-in.

๐Ÿ‡บ๐Ÿ‡ธ

CCPA-aware

Do-not-sell signals respected; per-customer data deletion endpoints exposed.

๐Ÿฅ

HIPAA-ready (Business)

BAA available for Business plan customers handling protected health information.

๐Ÿ“‹

SOC-friendly logs

Immutable audit logs & access trails compatible with SOC 2 Type II reviews.

๐ŸŒ

Data residency

Cloud regions in EU & West Africa. Self-hosted means you pick the region.

Where the data lives

Three deployment shapes. You choose.

โ˜๏ธ

OpsIQ Cloud ยท shared

Multi-tenant cloud at cloud.opsiqai.com. Per-tenant encryption keys, isolated databases per workspace, regional data residency. The fastest path to production.

  • Managed by us
  • Daily encrypted backups
  • 99.95% uptime SLA
๐Ÿข

OpsIQ Cloud ยท dedicated

Dedicated tenant database with isolated credentials, optional dedicated VM, custom domain. For teams whose contracts or compliance need stronger isolation than shared multi-tenant.

  • Dedicated database per tenant
  • Custom domain & SSL
  • Available on Business / Enterprise
๐Ÿ 

Self-hosted

Install OpsIQ on your own infrastructure. Same code as cloud, you keep the data path end-to-end. Activate with a license key, run the installer, you're operational in under an hour.

  • Full data sovereignty
  • Your backups, your retention
  • Air-gap compatible
Common questions

Trust FAQ.

Do you train AI models on our data?

No. We do not train any model on customer data. AI calls hit Anthropic, OpenAI or your chosen provider with the live conversation context only โ€” providers' standard data handling applies (most don't train on API traffic by default).

Where are the cloud data centres?

Multi-tenant cloud runs in EU and West Africa today. Dedicated cloud customers can choose region at provisioning. Self-hosted customers run wherever they like.

How are API keys and webhook secrets stored?

Public API keys are stored in plaintext (they're meant to be shared); secret keys and webhook signing secrets are stored encrypted with AES-256 using a per-install key derived from your environment.

Can we delete a customer's data on request?

Yes. Every customer record exposes a "delete & export" button in the account portal. Operators can also call POST /v1/customers/{id}/erase programmatically. Audit log entries about the deletion itself are retained for 12 months for compliance review.

What happens during an incident?

Live status at /status. We notify affected customers within 30 minutes for any operational incident, post a public RCA within 5 business days, and credit cloud customers per the SLA terms.

How do you handle subprocessors?

The /compliance page lists every subprocessor (cloud infra, AI providers, payment gateways, email delivery), what data they handle, and where they sit. We notify customers in advance of any change.

Can I see exactly what the AI received and replied?

Yes. AI History (owner-only) records every admin / customer / writing turn with the exact rendered prompt, the AI response, the action result if any, the duration and the actor. Filter, search and export to CSV.

Need more?

Talk to us about your security review.

Whether you need a DPA, a custom BAA, a security questionnaire walked through, or a dedicated single-tenant cloud โ€” start the conversation and we'll get the right person on the call.