Skip to content
OpsSense
SECURITY

Trust is earned in writing.

Our security posture, stated plainly: what is certified, what is in progress, and how the platform and hardware are engineered either way.

COMPLIANCE POSTURE

Programs and alignments, stated honestly.

Language below is deliberate: a program is not a certificate, and we will not blur the line.

SOC 2 program

A SOC 2 Type II program is underway with an independent auditor. Report available to customers under NDA once issued.

ISO 27001-aligned

The information security management system follows ISO 27001 control structure. Certification is on the compliance roadmap.

HIPAA-capable

Architecture supports HIPAA-regulated deployments, including BAAs on Enterprise agreements, for healthcare customers in applicable regions.

PDPL-ready

Data handling is designed for Saudi PDPL requirements, including in-Kingdom residency, data-subject rights tooling, and processing records.

Platform controls

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • SSO via SAML/OIDC, provisioning via SCIM — Entra ID and Okta first-class
  • Role-based access control down to site, module, field, and action
  • Complete, immutable audit logs for every read-sensitive and write action
  • Tenant isolation with per-tenant encryption keys on private cloud
  • Data residency options: in-Kingdom (KSA), in-region (UAE), EU, US
  • Backups with tested restore procedures and defined RPO/RTO per tier
  • Agent governance: permissioned scopes, approval thresholds, reversible actions

Hardware security

  • Signed firmware with staged rollout and automatic rollback
  • TLS from the sensor: mutual authentication from device to platform
  • No inbound ports on OpsSense Edge — outbound-only connections
  • Per-device credentials; compromised devices are revoked individually
  • Local buffering keeps data integrity through network loss

See your operations run themselves.

A 30-minute walkthrough with an operations engineer. Your assets, your workflows, your questions.