Opsphere

SECURITY AT OPSPHERE

Security built into how Opsphere operates

We apply technical and organizational controls designed to protect the confidentiality, integrity and availability of data across the Opsphere platform.

Report a vulnerability

Layered safeguards for data and operations

Our security program combines preventive, detective and recovery controls. We describe the outcomes publicly while keeping sensitive implementation details private.

  • Encryption

    Data is encrypted in transit and at rest using controls appropriate to the service and data involved.

  • Infrastructure isolation

    Production infrastructure uses network isolation and access controls designed to limit unnecessary exposure.

  • Credentials and least privilege

    Credentials are managed through secure services, with access restricted according to least-privilege principles.

  • Audit and monitoring

    We maintain audit records and security monitoring to support visibility, investigation and accountability.

  • Backup and recovery

    Backups and recovery procedures support service resilience and restoration when needed.

  • Controlled change and vulnerabilities

    Infrastructure changes are automated, versioned and reviewed. We evaluate reported or identified vulnerabilities and prioritize corrective action according to risk.

Customer systems remain authoritative

Opsphere is read-only by default. It queries connected systems for evidence and correlates operational context without replacing the systems that own the underlying data.

  • Source systems remain authoritative for logs, metrics, traces, code and infrastructure state.
  • Access is scoped to the tenant, account and environment involved.
  • Recommendations remain recommendations; production changes require explicit user action and authorization.
  • Operational evidence, inference, confidence and unknowns remain distinguishable.

Security evolves with the platform

We review and improve technical and organizational controls as Opsphere evolves. Established application-security guidance, including OWASP resources, informs the ongoing expansion and verification of our security program.

This statement describes continuous progress; it does not claim complete OWASP compliance or a certification.

Explore the OWASP ASVS reference

Report a potential vulnerability

If you believe you have found a security vulnerability affecting Opsphere, please report it responsibly and avoid accessing, changing or sharing data that is not yours.

What helps us investigate

  • A clear description of the issue and its potential impact.
  • The affected URL, product area or feature.
  • Reproduction steps using the minimum access necessary.
  • Relevant timestamps and supporting evidence with sensitive data removed.

How we handle reports

We review reports, validate their scope and prioritize corrective action according to risk. We may contact you for clarification or additional evidence.

We ask reporters to keep findings confidential while we investigate and coordinate any appropriate disclosure.

DIRECT ANSWERS

Key facts about Opsphere security

A concise, verifiable summary based on the capabilities and operating boundaries described on this page.

How does Opsphere protect data and operations?
Opsphere applies layered controls including encryption, infrastructure isolation, least-privilege access, centralized credential management, audit logging, monitoring, backups and controlled infrastructure changes.
How are Opsphere security controls maintained?
Security controls are reviewed as the platform evolves, while implementation details that could increase operational risk remain private. Potential vulnerabilities can be reported confidentially to security@opsphere.io.
Does Opsphere change production systems?
Opsphere is read-only by default. It queries connected source systems, correlates evidence and recommends next steps; source systems remain authoritative.