Trust & Security

Built by auditors. Secured like we'd demand of any vendor.

Opal holds your control environment, your evidence, and your investigations. We treat that responsibility the way you would — because we've been on your side of the vendor review.

01
Data protection

Your data, protected in transit and at rest.

US hosting on AWS

Opal runs on Amazon Web Services in US regions, inheriting AWS's physical security, environmental controls, and infrastructure certifications.

Encrypted everywhere

All traffic is encrypted in transit with TLS 1.2 or higher — no unencrypted access paths exist. All customer data is encrypted at rest with AES-256.

Isolated & backed up

Each customer's data is logically isolated. Automated encrypted backups run daily and are tested for restorability.

02
Access & authentication

Least privilege, enforced and logged.

Single sign-on

SSO via SAML 2.0, supported on every plan — never paywalled.

Multi-factor authentication

Available for all accounts.

Role-based access

Granular roles control what each user can see and do — testers, control owners, reviewers, executives, and admins each get what their role requires and nothing more.

Full activity logging

Every user action in Opal is logged at the user level, and admins can review what any user is doing or has done. The audit trail we sell you is the one we run on.

Our own access

Opal personnel access to customer data is restricted to defined support purposes, logged, and reviewed.

03
AI data practices

How AI touches your data — and how it doesn't.

Your data is not used to train AI models. Customer data is never used to train Opal's models or any third party's models.

Enterprise-grade processing

AI processing occurs under enterprise agreements with our AI providers, on US-based infrastructure. Those providers appear on our subprocessor list like every other vendor that touches customer data.

Human acceptance gate

Nothing the AI produces becomes part of your formal record until a human on your team reviews and accepts it. AI drafts are held separately until accepted.

Traceability

AI-assisted content is identifiable as such in the record — so when your external auditors ask how AI touched the workpapers, you have a clean answer.

04
Development & operations

Built carefully, in the US.

US-based development

Opal is designed, developed, and operated by a US-based team.

Secure development

Code changes are reviewed before deployment, with automated testing and dependency vulnerability scanning.

Vulnerability management

Automated scanning, plus independent penetration testing commissioned annually.

Change management

Production changes follow a documented process with rollback capability.

Incident response

We maintain a documented incident response plan with defined severity levels and customer notification commitments.

05
Availability & continuity

There when your deadlines are.

Documented disaster recovery procedures with defined recovery objectives, tested regularly.

Your data is exportable by you, at any time, in standard formats. If Opal ever ceased operations, contractual terms guarantee a data retrieval window. Your data is never hostage.

06
Compliance roadmap

Practicing what we sell.

Opal is preparing for SOC 2 examination. Our security practices are documented and available for vendor review today.

We run our own compliance program on Opal — our controls, our policies, our vendor reviews, our incident response, all managed in the product we sell. When we say it's built for real programs, we mean we bet our own on it.

07
Privacy

Your data is yours. Full stop.

Ownership

Customers own their data. We claim no rights to it beyond operating the service.

No selling, no sharing

We do not sell customer data or share it with third parties except the subprocessors required to operate Opal.

Data Processing Agreement

A DPA is available for all customers.

Subprocessors

We publish our subprocessor list and notify customers before adding new ones.

Retention & deletion

Customer data is retained for the life of the subscription and deleted after termination — on request or by default. Deletion certificates available on request.

Breach notification

We notify affected customers of a confirmed data breach without undue delay, and no later than 72 hours after confirmation.

Employee data

Where surveys and whistleblower modules process employee personal data, you act as data controller and Opal as processor — the DPA covers this.

Found something? Tell us.

We welcome good-faith security research and won't pursue action against good-faith researchers. For vulnerability reports, security questionnaires, and vendor reviews:

info@opalgrc.com