Security
Last updated: 10 October 2026
Opverio holds your company profile, watchlists, saved opportunities, notes and team. This page explains how we keep that information separate, protected and recoverable, and how Opverio collects public information responsibly.
1. Your workspace stays yours
- Every customer works in its own workspace. The database itself enforces the separation (row-level security on every table), so a request made for one customer cannot read another customer's rows — even if a single page had a bug.
- Inside an account, access follows roles (owner, admin, member). Only owners and admins can change the company profile, team, billing and settings.
- Your watchlists, notes, opportunity statuses and feedback are never shared with other customers and are never used to train AI models.
2. Encryption
- In transit: all traffic to opverio.ai uses HTTPS (TLS), with HSTS so browsers never fall back to plain HTTP.
- At rest: the database is encrypted by our hosting provider (AES-256).
- Passwords are stored only as salted scrypt hashes, and sign-in sessions and API keys only as SHA-256 hashes; nobody, including our team, can read them back.
3. Sign-in and accounts
- Sign-in is rate-limited per network address and per account, and an account is locked temporarily after repeated failed attempts.
- Session cookies are HTTP-only and secure, and expire automatically.
- When our support team opens your workspace to help you (for example to set up a first watchlist), access is limited to a few hours, shown with a visible banner, cannot change your password and is written to the audit log.
4. Application security
- A strict Content Security Policy and other security headers protect against injected scripts and clickjacking; Opverio pages cannot be embedded in other websites.
- Pictures from news sources are loaded through Opverio, so your browser does not contact those websites and your address is not shared with them.
- Important actions are written to an audit log: sign-ins and failed sign-ins, password changes, team and role changes, API keys, data exports, billing and support access.
- Secrets are kept in our hosting provider's encrypted settings, never in code or logs.
- Payments are made on our payment provider's pages; Opverio never receives or stores card numbers.
5. Backups and recovery
- The database is copied every week into an encrypted backup (AES-256) that is stored separately from the application and kept for 90 days.
- Every backup is checked for completeness when it is made; a failed backup alerts our team.
6. AI
- AI features run on established AI providers under business terms that do not allow them to train on what we send. We send only what a task needs — public-source text and the parts of your company profile that the analysis uses.
- Answers in Ask come only from signals stored in your workspace and show the signals they cite; analysis is always labelled and never presented as fact.
- AI use is metered and capped per plan.
7. Responsible collection
- Opverio reads public sources only. It identifies itself, respects robots.txt and never bypasses logins, paywalls or CAPTCHAs.
- Our servers refuse to fetch addresses on private networks, so a link added to Opverio cannot be used to reach internal systems.
8. Infrastructure and compliance
- The application runs in the Singapore region of our cloud hosting provider. Our infrastructure providers are independently audited (SOC 2 and/or ISO 27001 reports); the providers we use are listed in the Privacy Policy.
- Opverio itself does not yet hold its own ISO 27001 or SOC 2 certification.
- Personal data is handled under Indonesia's Personal Data Protection Law (UU PDP No. 27/2022) and, where they apply, Singapore's and Malaysia's Personal Data Protection Acts.
- If a personal data breach affects you, we notify you and the authorities within the legal deadline: 3 × 24 hours under the UU PDP, within 3 calendar days of assessment to Singapore's Personal Data Protection Commission, and within 72 hours to Malaysia's Personal Data Protection Commissioner.
- Privacy questions, requests about your data and our data protection officer: privacy@opverio.ai. The Privacy Policy explains your rights.
9. Reporting a security issue
Found a security issue? Email hello@opverio.ai — we reply within two working days. Please do not access or change other customers' data while testing.