Security · Verifiable

Proven not just trusted.

OPSQAI is sovereign by design. Operational knowledge stays on the customer's Windows Server. Signed artifacts prove provenance. Every privileged action is recorded in a hash-chained audit log.

The guarantee

OPSQAI never sees operational customer knowledge. Documents, chats, embeddings and users live inside the customer install.

Twelve pillars

Security by construction.

Ed25519-signed licenses

Every license is an Ed25519-signed bundle. The install verifies it locally, offline. Revocation is durable and cryptographically bound to the installation identity.

Signed activation bundles

Activation bundles are signed by OPSQAI with a 90-day validity window. Expired bundles are refused; renewal is issued through the Customer Portal.

Hash-chained audit trail

Privileged and AI actions are appended to a hash-chained audit log. Any tampering breaks the chain and is detected on verification.

Certificate revocation list

OPSQAI maintains a signed CRL for licenses and activation bundles. The install checks it on heartbeat and refuses revoked artifacts.

Chunk-level ACL

Retrieval is enforced at the chunk level. Users only see grounded citations from documents their role and department allow.

Customer owns the data

Documents, embeddings, chats, users and configuration are stored inside the customer install. OPSQAI never sees operational customer knowledge.

Signed releases

Installer packages and update manifests are signed. The updater refuses any artifact that fails verification.

Encryption in transit and at rest

TLS everywhere via Caddy. PostgreSQL storage follows Windows Server policy. Backups can be encrypted end-to-end.

Append-only audit log

License issuance, ownership transfer, admin promotion, module activation — every privileged action is logged with actor, target and timestamp.

Role-based access

Workspace owner, admin, manager, supervisor, worker, viewer. Platform Super Admin is a separate, tightly-scoped OPSQAI role.

Single-tenant boundary

Every install is one customer. No shared databases, vector stores or AI keys — nothing crosses tenants.

GDPR aligned

EU-hosted cloud surfaces, DPA available on request, right-to-erasure procedures documented for both cloud metadata and on-prem content.

For People.Not Without Them.

The boundary

What crosses. What stays.

Cloud · OPSQAI-managed
  • · Customer & installation metadata
  • · License records and signing keys
  • · Release manifests and CRL
  • · Support conversations
On-prem · Customer-owned
  • · Documents, SOPs and embeddings
  • · Chat messages and AI audit records
  • · End-user accounts and roles
  • · Workspace configuration and AI keys
Procurement, InfoSec, compliance

Bring your questionnaire here.

We respond to security reviews from procurement, InfoSec and compliance teams.