Ownership
Customer, staff, and financial data in any system we run belongs to the client. We do not use it to train models. It is exported on request in open formats, and on offboarding we hand over documentation and remove our access.
Isolation
Multi-tenant systems isolate each business at the database row level, enforced server side and tested in continuous integration as a restricted role on every merge. A user cannot load another company's data by changing an id in a URL.
Access
Named accounts only, least privilege, two-factor on administrative access, credentials in a vault rather than in code, and a log of who did what. Offboarded people lose access the same day.
Backups and restores
Encrypted offsite backups, retention windows written down, and restores actually rehearsed on a clean machine on a schedule, with the time it took recorded.
What the AI may do alone
Every automated action has an approval boundary. Drafting a quote, scoring an applicant, or answering a call within your rules can be automatic. Sending money, hiring, and anything that binds the business is held for a human unless you decide otherwise. Every action is logged with the reasoning.
Calls and recordings
Voice agents disclose that they are automated where the law requires it. Recordings and transcripts are stored in the client's system, retained on the client's schedule, and never used to train models.
Payments
Card data never touches our servers. Hosted payment fields keep you in the lightest compliance scope. Gateway mode is verified in the database, never trusted from a dashboard, and charges are reconciled nightly against the processor.
Vendors
Hosting in the United States, business email, a font service, the model providers we route to per task. The current list is in every agreement and available on request.
Incidents
Error tracking reaches us before it reaches you. If something affects your data we tell you, in writing, with what happened and what we did.
Reporting a vulnerability
If you find a security problem in anything we run, email security@opralta.com with enough detail to reproduce it. We acknowledge within seventy-two hours, keep you updated while we fix it, and credit you if you want the credit. We will not pursue legal action against anyone who reports in good faith, stays within the scope of their own account or a test account, avoids privacy violations and service degradation, and gives us reasonable time before publishing. We do not run a paid bounty today; if that changes it will say so here.
Questions
Security questionnaires and procurement forms are answered by a founder: hello@opralta.com.
Buying with legal or finance involved? The procurement page carries payment, IP, liability and support terms in one place.