Trust & Security

Security

Last updated: June 24, 2026  ยท  OpsBox
Contractors trust OpsBox with contracts, vendor data, financial records, and project documents. We take that seriously. This page explains exactly how we protect your data โ€” not in vague marketing language, but in specifics.
๐Ÿ”’
Encryption Everywhere
All data is encrypted in transit and at rest using industry-standard encryption. Your data is never stored or transmitted in plain text.
๐Ÿ—
Tenant Isolation
Every organization is a completely isolated workspace enforced at multiple infrastructure layers. One customer's data cannot be accessed by another.
๐Ÿ›ก
Access Controls
Every request is authenticated and verified against your organization membership before any data is returned.
๐Ÿ“‹
Security Logging
Important actions are logged for audit and incident response. If something goes wrong, we know exactly what happened and when.

Data Isolation

Every OpsBox customer organization is isolated from every other at multiple layers of our infrastructure โ€” not just at the application level. This means that even in the event of an application-level bug, our underlying systems are designed to prevent one organization's data from being accessible to another.

Organization membership is verified on every request before any data is returned.

Encryption

Authentication and Access

Infrastructure and Vendors

OpsBox is built on a small stack of trusted infrastructure providers. We've chosen each one deliberately:

File Upload Security

Documents uploaded to OpsBox (bid PDFs, contracts, submittals) are validated for file type and size before processing. Files are stored in Supabase Storage with access controlled by your organization's RLS policies โ€” only members of your organization can access your uploaded files.

File uploads are scanned for basic malicious content. We accept PDF files only for document processing.

Security Monitoring and Logging

OpsBox maintains security logs that record important security-relevant actions. These logs are used for incident response and security monitoring.

We monitor for unusual patterns and will notify affected customers in the event of a confirmed security incident.

Incident Response

In the event of a confirmed data breach or security incident affecting customer data:

To report a security vulnerability or concern, email us at support@opsboxapp.com with "Security" in the subject line. We will respond within 24 hours.

Responsible Disclosure

If you discover a security vulnerability in OpsBox, we ask that you follow responsible disclosure practices:

In return, we commit to: acknowledging your report within 24 hours, keeping you informed of our progress, not pursuing legal action against good-faith researchers who follow these guidelines, and crediting you in our security acknowledgments if you wish.

What We Don't Do

Report a Security Issue

If you've found a security vulnerability in OpsBox or have concerns about how we handle your data, please contact us directly. We take every report seriously and will respond quickly.

support@opsboxapp.com โ€” include "Security" in the subject line

OpsBox