Production controls continue to mature during controlled customer deployments.
Security, privacy, governance, and service transparency.
Review how Operiin protects customer workspaces, workforce information, operational records, decision-support outputs, and account access — including the controls Operiin operates, the providers supporting the service, and the responsibilities customers retain.
Access is governed by authenticated organization, location, role, and user permissions.
Primary service regions and supporting provider locations are disclosed below.
Operiin outputs require authorized human review.
No independent security certification is claimed unless expressly published here.
Collect → Use → Store → Export → Retain → Delete
Operiin trust and service documentation
Each document has a defined purpose. Organization agreements, individual-user terms, data-processing obligations, security controls, and support policies are maintained separately to reduce ambiguity.
Security Overview
Tenant isolation, authenticated organization scope, row-level security, role permissions, audit records, file controls, and incident-response practices.
Privacy Notice
How Operiin handles account, workforce, operational, technical, billing, support, and website information.
Terms of Service
The organization-level agreement governing subscriptions, authorized use, customer responsibilities, decision-support boundaries, and platform ownership.
End User License Agreement
The individual-user license governing account access, credentials, authorized use, customer-directed processing, and interaction with Operiin outputs.
Data Processing Addendum
Processor terms, documented instructions, data categories, security measures, incidents, subprocessors, rights assistance, return, and deletion.
Subprocessor Registry
Providers supporting infrastructure, authentication, delivery, payments, communication, monitoring, and enabled integrations.
Data Location & Hosting
Primary service regions, provider infrastructure, backups, file storage, support access, and international-transfer mechanisms.
Compliance & Workforce Governance
Responsibility boundaries, workforce-data governance, human review, retention, employment compliance, and algorithmic-risk controls.
Acceptable Use Policy
Rules covering unauthorized access, credential sharing, scraping, reverse engineering, discriminatory use, interference, and improper output use.
Service Availability & Support
Beta support scope, production availability targets, maintenance, incident severity, exclusions, and custom-service options.
Vulnerability Disclosure
Instructions for confidentially reporting suspected vulnerabilities, access-control issues, or unintended data exposure.
Independent assurance: Not currently certified.
Operiin does not claim SOC 2, ISO 27001, or equivalent independent certification. The roadmap below states what operates today, what is being formalized next, and what is planned — without implying an assurance engagement that has not been scoped.
- Controlled-beta security baseline
- Organization-scoped RLS and role access
- Audit-event capture
- Subprocessor inventory
- Security and privacy policy baseline
- Incident-response process
- Formal control inventory
- Evidence-retention procedures
- Access-review process
- Vendor-risk reviews
- Backup and recovery testing
- Internal security assessment
- Independent readiness assessment
- SOC 2 examination scope evaluation
- Penetration testing
- Expanded enterprise assurance documentation
Request documentation or a security review.
Vendor questionnaires, control evidence, and architecture questions.
DPA / SCC requestExecutable DPA copies and Standard Contractual Clauses addenda.
Privacy requestAccess, correction, deletion, and other privacy-rights requests.
Subprocessor questionRegistry questions, change notices, and objections.
Vulnerability reportConfidential security reports — see the Vulnerability Disclosure policy.
Other trust questionAnything else — enterprise architecture reviews, NDA requests, procurement.
When requesting, include your work email, organization, role, location count, whether you are an existing or prospective customer, the requested material, and any procurement deadline or NDA requirement. Do not include passwords, authentication tokens, production employee records, payment-card information, or vulnerability exploit details in these requests— sensitive vulnerability information should use the dedicated security-reporting channel. security@, privacy@, and legal@operiin.com route to Operiin’s monitored support inbox during controlled beta.
Changelog
Provider identity disclosed (Wenraw Distributors, DBA Operiin); EULA, Vulnerability Disclosure, and Data Location & Hosting published; SLA renamed Service Availability & Support Policy; DPA annexes and SCC availability added; Workforce Decision Governance added; terminology standardized to Optional Modules.
Initial publication of the consolidated legal document set.
Clear controls. Clear ownership.
- Operate documented platform access controls.
- Maintain organization-scoped data handling.
- Protect service infrastructure and account access.
- Provide documented decision-support methodology.
- Investigate qualifying security incidents.
- Control authorized users, roles, and locations.
- Provide lawful and accurate workforce data.
- Configure applicable labor and operating rules.
- Apply human review before acting on outputs.
- Comply with employment, privacy, and labor law.
Need documentation or security review support?
Contact Operiin for beta security questionnaires, privacy requests, subprocessor questions, data-processing questions, or vulnerability reporting.