Trust & Security
Security
Last updated: June 24, 2026 ยท OpsBox
Contractors trust OpsBox with contracts, vendor data, financial records, and project documents. We take that seriously. This page explains exactly how we protect your data โ not in vague marketing language, but in specifics.
๐
Encryption Everywhere
All data is encrypted in transit and at rest using industry-standard encryption. Your data is never stored or transmitted in plain text.
๐
Tenant Isolation
Every organization is a completely isolated workspace enforced at multiple infrastructure layers. One customer's data cannot be accessed by another.
๐ก
Access Controls
Every request is authenticated and verified against your organization membership before any data is returned.
๐
Security Logging
Important actions are logged for audit and incident response. If something goes wrong, we know exactly what happened and when.
Data Isolation
Every OpsBox customer organization is isolated from every other at multiple layers of our infrastructure โ not just at the application level. This means that even in the event of an application-level bug, our underlying systems are designed to prevent one organization's data from being accessible to another.
Organization membership is verified on every request before any data is returned.
Encryption
- In transit โ all communication between your browser and OpsBox is encrypted using industry-standard transport security. All connections are HTTPS only.
- At rest โ all data stored in our database and file storage is encrypted at rest using industry-standard encryption. This includes your project data, vendor records, uploaded documents, and all other information.
- Passwords โ we never store plain text passwords. We use industry-standard cryptographic password hashing.
Authentication and Access
- Request verification โ every request is authenticated and verified against your organization membership before any data operation is performed
- Session management โ sessions are managed using secure, httpOnly cookies
- Rate limiting โ API endpoints are rate limited to prevent brute force attacks and unauthorized access attempts
- Invite-only team access โ team members can only join your organization via explicit invitation. There is no way to discover or join an organization without being invited by an existing member.
Infrastructure and Vendors
OpsBox is built on a small stack of trusted infrastructure providers. We've chosen each one deliberately:
- Supabase โ database, authentication, and file storage. Maintains SOC 2 Type II compliance. Data stored in US-based data centers.
- Vercel โ application hosting and serverless functions. Vercel maintains SOC 2 Type II compliance.
- Anthropic โ powers the OpsBox Advisor. Anthropic does not use API inputs to train models and does not retain data beyond processing each request.
- Stripe โ payment processing. Stripe is PCI DSS Level 1 certified. We never see or store your full card details.
- OpenAI โ used for document embeddings only. Text from uploaded documents is processed to create searchable vector representations.
File Upload Security
Documents uploaded to OpsBox (bid PDFs, contracts, submittals) are validated for file type and size before processing. Files are stored in Supabase Storage with access controlled by your organization's RLS policies โ only members of your organization can access your uploaded files.
File uploads are scanned for basic malicious content. We accept PDF files only for document processing.
Security Monitoring and Logging
OpsBox maintains security logs that record important security-relevant actions. These logs are used for incident response and security monitoring.
We monitor for unusual patterns and will notify affected customers in the event of a confirmed security incident.
Incident Response
In the event of a confirmed data breach or security incident affecting customer data:
- We will notify affected customers within 72 hours of confirming the incident
- We will provide a clear description of what happened, what data was affected, and what we are doing about it
- We will take immediate steps to contain the incident and prevent further exposure
- We will cooperate with any applicable regulatory requirements
To report a security vulnerability or concern, email us at support@opsboxapp.com with "Security" in the subject line. We will respond within 24 hours.
Responsible Disclosure
If you discover a security vulnerability in OpsBox, we ask that you follow responsible disclosure practices:
- Email support@opsboxapp.com with "Security Vulnerability" in the subject line before public disclosure
- Give us a reasonable amount of time (typically 90 days) to investigate and remediate before going public
- Do not access, modify, or delete data that does not belong to you
- Do not perform denial-of-service attacks or disruptive testing
In return, we commit to: acknowledging your report within 24 hours, keeping you informed of our progress, not pursuing legal action against good-faith researchers who follow these guidelines, and crediting you in our security acknowledgments if you wish.
What We Don't Do
- We do not sell your data to anyone, ever
- We do not use your project or vendor data to train AI models
- We do not allow employees to access customer data without explicit authorization and a documented reason
- We do not store payment card details โ Stripe handles all payment data
- We do not run advertising networks or share data with marketing platforms