Security
Security
Last updated: 2026-06-28
Security is foundational to how Opserly is built, not a feature added on top. This page summarizes the controls we have in place today.
Infrastructure
• Hosted on secure cloud infrastructure, with data stored in a managed, encrypted database inside a private network.
• All traffic between your browser and Opserly is encrypted in transit via TLS/HTTPS.
• Application infrastructure scales automatically to meet demand and is patched continuously on a managed, secure runtime.
Data protection
• Sensitive fields — including Social Security Numbers and bank account details — are encrypted at rest, separate from general application data.
• Role-based access control (RBAC) restricts every module to only the users who need it, down to view/create/edit/delete granularity.
• A complete audit log records changes to financial records, so every edit is traceable to a user and a timestamp.
Payments and banking
Opserly never stores raw card numbers or full bank credentials. Card payments are processed by Stripe and bank linking is handled by Plaid — both are payment infrastructure providers used by thousands of companies and certified to the relevant industry security standards for their respective services. Vendors can link their own bank account through a one-time Plaid-hosted link without ever sharing credentials with Opserly or your team directly.
Data isolation
Each organization's data is logically isolated and scoped by organization at the database layer — one customer's records are never visible to another.
Sub-processors
• Amazon Web Services — hosting and infrastructure
• Plaid — bank account linking and ACH transfers
• Stripe — customer invoice payment processing
• DocuSign — e-signature for quotes and contracts
Reporting a security issue
If you believe you have found a security vulnerability, please email admin@opserly.com with details. We take all reports seriously and will respond promptly.