
Built by auditors. Secured like we'd demand of any vendor.
Opal holds your control environment, your evidence, and your investigations. We treat that responsibility the way you would — because we've been on your side of the vendor review.
Your data, protected in transit and at rest.
Opal runs on Amazon Web Services in US regions, inheriting AWS's physical security, environmental controls, and infrastructure certifications.
All traffic is encrypted in transit with TLS 1.2 or higher — no unencrypted access paths exist. All customer data is encrypted at rest with AES-256.
Each customer's data is logically isolated. Automated encrypted backups run daily and are tested for restorability.
Least privilege, enforced and logged.
How AI touches your data — and how it doesn't.
Your data is not used to train AI models. Customer data is never used to train Opal's models or any third party's models.
AI processing occurs under enterprise agreements with our AI providers, on US-based infrastructure. Those providers appear on our subprocessor list like every other vendor that touches customer data.
Nothing the AI produces becomes part of your formal record until a human on your team reviews and accepts it. AI drafts are held separately until accepted.
AI-assisted content is identifiable as such in the record — so when your external auditors ask how AI touched the workpapers, you have a clean answer.
Built carefully, in the US.
Opal is designed, developed, and operated by a US-based team.
Code changes are reviewed before deployment, with automated testing and dependency vulnerability scanning.
Automated scanning, plus independent penetration testing commissioned annually.
Production changes follow a documented process with rollback capability.
We maintain a documented incident response plan with defined severity levels and customer notification commitments.
There when your deadlines are.
Documented disaster recovery procedures with defined recovery objectives, tested regularly.
Your data is exportable by you, at any time, in standard formats. If Opal ever ceased operations, contractual terms guarantee a data retrieval window. Your data is never hostage.
Practicing what we sell.
Opal is preparing for SOC 2 examination. Our security practices are documented and available for vendor review today.
We run our own compliance program on Opal — our controls, our policies, our vendor reviews, our incident response, all managed in the product we sell. When we say it's built for real programs, we mean we bet our own on it.
Your data is yours. Full stop.
Customers own their data. We claim no rights to it beyond operating the service.
We do not sell customer data or share it with third parties except the subprocessors required to operate Opal.
A DPA is available for all customers.
We publish our subprocessor list and notify customers before adding new ones.
Customer data is retained for the life of the subscription and deleted after termination — on request or by default. Deletion certificates available on request.
We notify affected customers of a confirmed data breach without undue delay, and no later than 72 hours after confirmation.
Where surveys and whistleblower modules process employee personal data, you act as data controller and Opal as processor — the DPA covers this.

Found something? Tell us.
We welcome good-faith security research and won't pursue action against good-faith researchers. For vulnerability reports, security questionnaires, and vendor reviews:
info@opalgrc.com