Trust

Security and compliance

How we isolate your data, protect secrets, and handle information collected by the free scan.

Tenant isolation

Every database query runs through a session bound by row-level security to your organisation. No query can read or write another organisation's data, by construction — not just by application logic.

Encrypted secrets

SSH keys, passwords and tokens are encrypted at rest with AES-256-GCM, with an optional HashiCorp Vault backend for organisations that manage their own key material. Secrets are never logged and are masked in job output, engine events and variables.

Argon2id + 2FA

Passwords are hashed with Argon2id. Two-factor authentication (TOTP) is available per account and can be required organisation-wide, with recovery codes for account recovery.

Full audit log

Every mutation — who did what, when, and from where — is recorded to an append-only activity log, retained for your plan's retention window.

Proprietary engine

Provisioning, audits, remediation and deployments run on our own OpsDeck Engine: SSH/agent transports, a declarative Blueprint DSL, and our own action library. No GPL-licensed or third-party automation tool is used anywhere in the product.

Read-only free scanner

The free security scan only ever reads configuration, running processes and package metadata. It never modifies a file, installs a package or restarts a service.

Compliance

India compliance

We continue to build out CERT-In / DPDP technical checks as part of our compliance programme for customers operating in India. This covers technical controls — it is not a claim of India-based hosting.

Data retention: free-scan reports are kept for 30 days (7 days if the email is never verified). Consented marketing leads are kept for up to 24 months. Signed-in organisation data follows your plan's configured log and metrics retention.

Disclosure

Responsible disclosure

Found a security issue? We want to know.

Email security@opsdeck.example (placeholder address)

Please include reproduction steps and impact. We aim to acknowledge reports within two business days.

Retention

Data retention at a glance

7 days

Unverified free scan

30 days

Verified free scan

Up to 24 months

Consented lead data