Proven not just trusted.
OPSQAI is sovereign by design. Operational knowledge stays on the customer's Windows Server. Signed artifacts prove provenance. Every privileged action is recorded in a hash-chained audit log.
OPSQAI never sees operational customer knowledge. Documents, chats, embeddings and users live inside the customer install.
Security by construction.
Every license is an Ed25519-signed bundle. The install verifies it locally, offline. Revocation is durable and cryptographically bound to the installation identity.
Activation bundles are signed by OPSQAI with a 90-day validity window. Expired bundles are refused; renewal is issued through the Customer Portal.
Privileged and AI actions are appended to a hash-chained audit log. Any tampering breaks the chain and is detected on verification.
OPSQAI maintains a signed CRL for licenses and activation bundles. The install checks it on heartbeat and refuses revoked artifacts.
Retrieval is enforced at the chunk level. Users only see grounded citations from documents their role and department allow.
Documents, embeddings, chats, users and configuration are stored inside the customer install. OPSQAI never sees operational customer knowledge.
Installer packages and update manifests are signed. The updater refuses any artifact that fails verification.
TLS everywhere via Caddy. PostgreSQL storage follows Windows Server policy. Backups can be encrypted end-to-end.
License issuance, ownership transfer, admin promotion, module activation — every privileged action is logged with actor, target and timestamp.
Workspace owner, admin, manager, supervisor, worker, viewer. Platform Super Admin is a separate, tightly-scoped OPSQAI role.
Every install is one customer. No shared databases, vector stores or AI keys — nothing crosses tenants.
EU-hosted cloud surfaces, DPA available on request, right-to-erasure procedures documented for both cloud metadata and on-prem content.
For People.Not Without Them.
What crosses. What stays.
- · Customer & installation metadata
- · License records and signing keys
- · Release manifests and CRL
- · Support conversations
- · Documents, SOPs and embeddings
- · Chat messages and AI audit records
- · End-user accounts and roles
- · Workspace configuration and AI keys
Bring your questionnaire here.
We respond to security reviews from procurement, InfoSec and compliance teams.