Trust
Security and compliance
How we isolate your data, protect secrets, and handle information collected by the free scan.
Tenant isolation
Every database query runs through a session bound by row-level security to your organisation. No query can read or write another organisation's data, by construction — not just by application logic.
Encrypted secrets
SSH keys, passwords and tokens are encrypted at rest with AES-256-GCM, with an optional HashiCorp Vault backend for organisations that manage their own key material. Secrets are never logged and are masked in job output, engine events and variables.
Argon2id + 2FA
Passwords are hashed with Argon2id. Two-factor authentication (TOTP) is available per account and can be required organisation-wide, with recovery codes for account recovery.
Full audit log
Every mutation — who did what, when, and from where — is recorded to an append-only activity log, retained for your plan's retention window.
Proprietary engine
Provisioning, audits, remediation and deployments run on our own OpsDeck Engine: SSH/agent transports, a declarative Blueprint DSL, and our own action library. No GPL-licensed or third-party automation tool is used anywhere in the product.
Read-only free scanner
The free security scan only ever reads configuration, running processes and package metadata. It never modifies a file, installs a package or restarts a service.
Compliance
India compliance
We continue to build out CERT-In / DPDP technical checks as part of our compliance programme for customers operating in India. This covers technical controls — it is not a claim of India-based hosting.
Data retention: free-scan reports are kept for 30 days (7 days if the email is never verified). Consented marketing leads are kept for up to 24 months. Signed-in organisation data follows your plan's configured log and metrics retention.
Disclosure
Responsible disclosure
Found a security issue? We want to know.
Email security@opsdeck.example (placeholder address)
Please include reproduction steps and impact. We aim to acknowledge reports within two business days.
Retention
Data retention at a glance
7 days
Unverified free scan
30 days
Verified free scan
Up to 24 months
Consented lead data