Security Trust Center
Enterprise security.
Zero compromises.
Your customers share sensitive information with Operator AI — medical needs, legal matters, financial questions. We protect that data with enterprise-grade security at every layer.
Encryption
Data protected at rest and in transit
AES-256-GCM encryption for all stored data including conversations, lead profiles, and documents
TLS 1.3 for all API communications. HSTS enforced on all public endpoints
Encrypted database volumes with key management through dedicated KMS
All database backups are encrypted using the same AES-256 standard
Encryption keys are rotated quarterly. Master keys stored in hardware security modules
Tenant Isolation
Your data never touches another business
Every database record includes an org_id constraint. Cross-tenant queries are structurally impossible
Enterprise customers can request dedicated schemas for complete logical separation
All API routes validate org_id from authenticated session tokens before any data access
Knowledge base, conversation history, and lead data are scoped per organization. No cross-contamination
File uploads are stored in organization-scoped storage buckets with separate access policies
Authentication & Authorization
Identity verified at every layer
In-House Auth — Argon2id password hashing and database-backed session isolation
Short-lived JWT tokens (15 minutes). Refresh tokens rotate on every use
MFA available for all users. Enforced for Admin and Agency roles
Owner, Admin, Member, and Viewer roles with granular permission scopes
SAML 2.0 SSO available on Enterprise plans. Supports Okta, Azure AD, Google Workspace
Infrastructure Security
Built on hardened cloud infrastructure
AWS / Vercel infrastructure with SOC2 and ISO 27001 certification
Cloudflare DDoS mitigation and WAF on all public endpoints
Database servers are in private VPCs. No public database endpoints
Docker containers run as non-root users. Read-only file systems where possible
Automated dependency scanning on every code push. Critical CVEs patched within 24 hours
Annual third-party penetration testing. Results shared with Enterprise customers on request
Backups & Recovery
Your data is always recoverable
Automated database backups every 6 hours. Transaction logs backed up every 15 minutes
30-day backup retention for all plans. 1-year retention for Enterprise
Backups stored in geographically separate regions from production
Recovery procedures tested monthly. Target RTO: 4 hours, RPO: 15 minutes
Enterprise customers can request point-in-time recovery to any moment in the past 30 days
Audit Logs
Complete visibility into every action
Every administrative action logged with timestamp, user ID, IP address, and action details
All sensitive data access (conversations, lead data, billing) is logged and searchable
Login attempts, MFA events, password changes, and session creation are all logged
Audit logs retained for 12 months minimum. Extended retention available on Enterprise
Audit logs exportable as CSV/JSON. API access available for SIEM integration
Compliance Architecture
Designed for regulated industries
In preparation. Architecture built to SOC2 Trust Service Criteria. Expected certification Q4 2025
Full GDPR compliance. Data processing agreements (DPAs) available on request. Right to erasure supported
BAA available for medical practices on Business/Enterprise plans. End-to-end encryption and audit logs support HIPAA workflows
Enterprise customers can request data residency in specific regions (US, EU, India)
Minimal data collection principle. No conversation data used for AI model training without explicit consent
Responsible Disclosure
Found a security vulnerability?
We welcome responsible security researchers. If you've discovered a potential vulnerability in Operator, please report it to us privately before any public disclosure.
Security Contact
Response Time
Within 24 hours, 7 days a week
Please encrypt sensitive reports using our PGP key, available on request. Include a clear description of the vulnerability, steps to reproduce, and potential impact.
Certifications
Planned certifications
We are actively pursuing formal certifications in 2025.
SOC2 Type II
Q4 2025
70% complete
ISO 27001
Q1 2026
30% complete
HIPAA BAA
Available Now
100% complete
GDPR DPA
Available Now
100% complete
Security questions before you buy?
Our team is happy to walk through our security architecture, answer compliance questions, or provide documentation for your procurement process.