Security at Operiq
This page is maintained by Operiq to answer common security and privacy questions about the platform. It describes controls that are enabled today — it is not a certification or an independent audit.
Authentication
Email and password sign-in with hashed credentials, plus Google sign-in. Sessions are token-based and expire automatically. Anonymous sign-ups are disabled.
Access control
Every table enforces row-level security. Users can read and write only records belonging to their own account, checked on the server on every request.
Encryption
Traffic is served over TLS. Data at rest is encrypted by the managed database platform. Secrets are stored in a managed secret store and never in application code.
Hosting
Operiq runs on managed cloud infrastructure with a managed Postgres database. Backups and patching are handled by the platform provider.
Roles and privileges
Application roles are stored separately from user profiles and evaluated server-side, so a client cannot elevate its own permissions.
AI data handling
Photos and job details sent for AI analysis are processed to return a result to your account. AI output is advisory and never applied to your records automatically.
Shared responsibility
Operiq is responsible for the platform: application security, access enforcement, encryption in transit and the hosting configuration. You are responsible for account hygiene: who you invite, the roles you assign, the strength of your passwords and the data you choose to upload. Our infrastructure providers are responsible for the underlying cloud and database platform.
Subprocessors
Operiq uses managed cloud hosting, a managed Postgres database and authentication service, and an AI model gateway for photo and property analysis. A current subprocessor list is available on request.
Data retention and deletion
Your data remains available while your account is active and for 30 days after cancellation, after which it is scheduled for deletion. You can request an export or an earlier deletion at any time.
Reporting a vulnerability
If you believe you have found a security issue, contact us before disclosing it publicly. Include reproduction steps and the affected URL. We acknowledge reports and keep the reporter updated through resolution.
Operiq does not currently claim SOC 2, ISO 27001, HIPAA or PCI certification. The architecture is built toward SOC 2 readiness. If your procurement process requires attested compliance, contact us and we will tell you honestly where we stand.
