Back to Home

Security & Data Protection

The controls below cover both short-lived Scanner sessions and ongoing Watchdog monitoring; their token and retention lifecycles are different.

🛡️ Data-use commitments

We limit access and disclosure to the purposes described in the Privacy Policy, the connector notice, and the service you request. No online service can responsibly promise zero risk, so we describe the controls and boundaries instead of offering an absolute security guarantee.

  • OpsLab does not sell personal or operational data.
  • Customer data is not intentionally exposed to other customers; tenant and session identifiers are used to scope application access.
  • Connector content is not used for advertising or cross-site behavioural targeting.
  • Optional first-party product analytics requires a separate browser choice and is not a condition of essential service use.
  • Scanner sessions use a 72-hour expiry; Watchdog, account, support, consent, and payment records use the longer lifecycle described in the Privacy Policy.
  • Service providers receive the limited data needed for hosting, communication, payment, connected-platform access, and AI-assisted service functions.

Encryption Architecture

  • AES-256-GCM application-level encryption — OAuth tokens and PKCE verifiers are encrypted before storage.
  • HTTPS/TLS protects supported traffic between the browser, OpsLab services, and provider APIs.
  • PKCE is used for provider flows that support it; signed state values protect connector and session binding during OAuth.
  • Production secrets and encryption keys are supplied through deployment configuration rather than client-side code.

Access Control

  • Monitoring connectors are designed for read-oriented, least-privilege access, but the exact permission model is determined by each provider.
  • OAuth screens and key-setup instructions should be reviewed before authorization; connect only the organization and resources you are allowed to share.
  • Some provider integrations may require an administrator to install an app even when its operational use is read-oriented.
  • You control which tools to connect and can revoke credentials at the provider; contact OpsLab for deletion of stored connector data.

Token Lifecycle

  • A provider issues an OAuth token, or you submit a dedicated API credential through the secure connector form.
  • Stored connector credentials are encrypted at application level and decrypted only when an authorized service operation needs them.
  • Scanner credentials are cleared after the one-off analysis and the Scanner session expires after 72 hours.
  • Watchdog credentials, including refresh tokens where supported, persist while the approved continuous connection needs them.
  • Provider revocation blocks future successful access; full stored-data deletion is handled through a verified request.

Data Lifecycle

  • Scanner session created → its 72-hour expiry begins.
  • Scanner analysis → provider fields are processed to produce temporary metrics and a report.
  • Scanner report deletion → the report control deletes that Scanner session, its temporary connector rows, session-linked optional events, and linked aggregate-report cache entry; it does not delete a separate account or Watchdog tenant.
  • Watchdog connected → approved credentials and derived monitoring history remain available for recurring sync and service delivery.
  • Account and security sessions → expire on their configured schedule; payment and consent records may need longer legal or contractual retention.
  • Verified privacy request → relevant data is exported, corrected, disconnected, deleted, or retained with an explanation based on the request and applicable obligations.

LLM Data Handling

  • OpsLab uses the OpenAI API for reports, recommendations, chat, search embeddings, and other AI-assisted service functions.
  • Requests are intended to include the metrics and limited evidence needed for the task; content-level evidence can be included only where the connector/service scope permits it.
  • OpsLab does not use customer connector data to train its own general-purpose model. OpenAI processes API requests under its applicable API data terms.
  • A deterministic cache of aggregate Scanner report output can remain for up to 30 days; Watchdog caches and indexes follow their service retention and deletion controls.

Infrastructure Security

  • Production services are hosted on Hetzner infrastructure in Germany; Railway is used for the EU test environment.
  • PostgreSQL access is restricted to the service environment and protected connections.
  • Application authorization scopes Scanner sessions, client accounts, operator functions, and Watchdog tenants separately.
  • Environment variables for all secrets (API keys, encryption keys, OAuth credentials).
  • Security headers: X-Frame-Options DENY, X-Content-Type-Options nosniff, strict Referrer-Policy.

Privacy and assurance posture

  • We aim to apply data minimization, purpose limitation, recorded choices, and request handling appropriate to the service.
  • The service stores personal data for accounts, contacts, support, consent, authentication, and payments; the Privacy Policy describes those categories.
  • Enterprise customers can request a discussion of data-processing terms and connector scope before onboarding.
  • This page describes current controls and is not a claim of ISO, SOC 2, GDPR, or other formal certification.

Security Questions?

For security-related inquiries or to report a vulnerability, contact janedavydiuk@opslab.uk.