Security Trust Center

Enterprise security.
Zero compromises.

Your customers share sensitive information with Operator AI — medical needs, legal matters, financial questions. We protect that data with enterprise-grade security at every layer.

AES-256 Encryption
Tenant Isolation
99.9% Uptime
SOC2 Ready
GDPR Compliant

Encryption

Data protected at rest and in transit

Data at Rest

AES-256-GCM encryption for all stored data including conversations, lead profiles, and documents

Data in Transit

TLS 1.3 for all API communications. HSTS enforced on all public endpoints

Database Encryption

Encrypted database volumes with key management through dedicated KMS

Backup Encryption

All database backups are encrypted using the same AES-256 standard

Key Management

Encryption keys are rotated quarterly. Master keys stored in hardware security modules

Tenant Isolation

Your data never touches another business

Row-level Security

Every database record includes an org_id constraint. Cross-tenant queries are structurally impossible

Schema Isolation

Enterprise customers can request dedicated schemas for complete logical separation

API Isolation

All API routes validate org_id from authenticated session tokens before any data access

AI Isolation

Knowledge base, conversation history, and lead data are scoped per organization. No cross-contamination

Storage Isolation

File uploads are stored in organization-scoped storage buckets with separate access policies

Authentication & Authorization

Identity verified at every layer

Authentication Provider

In-House Auth — Argon2id password hashing and database-backed session isolation

Session Management

Short-lived JWT tokens (15 minutes). Refresh tokens rotate on every use

Multi-Factor Authentication

MFA available for all users. Enforced for Admin and Agency roles

Role-Based Access Control

Owner, Admin, Member, and Viewer roles with granular permission scopes

SSO Support

SAML 2.0 SSO available on Enterprise plans. Supports Okta, Azure AD, Google Workspace

Infrastructure Security

Built on hardened cloud infrastructure

Cloud Provider

AWS / Vercel infrastructure with SOC2 and ISO 27001 certification

DDoS Protection

Cloudflare DDoS mitigation and WAF on all public endpoints

Network Segmentation

Database servers are in private VPCs. No public database endpoints

Container Security

Docker containers run as non-root users. Read-only file systems where possible

Vulnerability Scanning

Automated dependency scanning on every code push. Critical CVEs patched within 24 hours

Penetration Testing

Annual third-party penetration testing. Results shared with Enterprise customers on request

Backups & Recovery

Your data is always recoverable

Backup Frequency

Automated database backups every 6 hours. Transaction logs backed up every 15 minutes

Retention Period

30-day backup retention for all plans. 1-year retention for Enterprise

Geographic Replication

Backups stored in geographically separate regions from production

Recovery Testing

Recovery procedures tested monthly. Target RTO: 4 hours, RPO: 15 minutes

Point-in-time Recovery

Enterprise customers can request point-in-time recovery to any moment in the past 30 days

Audit Logs

Complete visibility into every action

Admin Actions

Every administrative action logged with timestamp, user ID, IP address, and action details

Data Access Logs

All sensitive data access (conversations, lead data, billing) is logged and searchable

Auth Events

Login attempts, MFA events, password changes, and session creation are all logged

Retention

Audit logs retained for 12 months minimum. Extended retention available on Enterprise

Export

Audit logs exportable as CSV/JSON. API access available for SIEM integration

Compliance Architecture

Designed for regulated industries

SOC2 Type II

In preparation. Architecture built to SOC2 Trust Service Criteria. Expected certification Q4 2025

GDPR

Full GDPR compliance. Data processing agreements (DPAs) available on request. Right to erasure supported

HIPAA Considerations

BAA available for medical practices on Business/Enterprise plans. End-to-end encryption and audit logs support HIPAA workflows

Data Residency

Enterprise customers can request data residency in specific regions (US, EU, India)

Privacy by Design

Minimal data collection principle. No conversation data used for AI model training without explicit consent

Responsible Disclosure

Found a security vulnerability?

We welcome responsible security researchers. If you've discovered a potential vulnerability in Operator, please report it to us privately before any public disclosure.

We will acknowledge your report within 24 hours
We will investigate and provide status updates
We will credit researchers in our security acknowledgements
We will not take legal action against good-faith researchers

Security Contact

Response Time

Within 24 hours, 7 days a week

Please encrypt sensitive reports using our PGP key, available on request. Include a clear description of the vulnerability, steps to reproduce, and potential impact.

Certifications

Planned certifications

We are actively pursuing formal certifications in 2025.

SOC2 Type II

Q4 2025

70% complete

ISO 27001

Q1 2026

30% complete

HIPAA BAA

Available Now

100% complete

GDPR DPA

Available Now

100% complete

Security questions before you buy?

Our team is happy to walk through our security architecture, answer compliance questions, or provide documentation for your procurement process.