Trust

Security

Effective 29 September 2026

This page describes the controls built into our products and how to report a vulnerability. It describes what is implemented today; we do not currently hold third-party certifications such as SOC 2 or ISO 27001. Customers who need a security questionnaire completed can write to security@opsmeld.com.

01Tenant isolation

  • Every customer has its own workspace. Every read and write is scoped to that workspace in application code.
  • PostgreSQL row-level security policies enforce the same boundary in the database, so a missed filter in code cannot return another customer’s rows.
  • Records cannot be written without a workspace identifier; there is no shared default workspace.
  • Requests for another workspace’s records are refused with a not-found or forbidden response.

02Authentication and sessions

  • Passwords are hashed with bcrypt (cost factor 12). We never store or log plain-text passwords.
  • Sessions use signed tokens in HTTP-only, SameSite=Strict cookies, sent only over HTTPS in production, and expire after 8 hours.
  • Sign-in is limited to 10 attempts and password reset to 5 requests per 15 minutes.
  • Sign-in and password-reset responses do not reveal whether an account exists.
  • Account status and workspace membership are re-checked on every API request, so suspending a user takes effect immediately.

03Access control and audit

  • Role-based permissions for requesters, agents, managers, and administrators are enforced on the server for every route.
  • The last administrator of a workspace cannot be removed or demoted, so no workspace is left unmanaged.
  • Changes, approvals, assignments, and administrative actions are written to an audit log with the user and time.
  • OpsMeld staff access to customer workspaces is limited to authorised personnel for support, operations, and security.

04Infrastructure

  • Cloud workspaces run on managed hosting and a managed PostgreSQL service. Traffic is encrypted in transit with TLS.
  • Asset health checks refuse to contact private, loopback, and cloud-metadata addresses, to prevent server-side request forgery.
  • The providers we rely on are listed on our subprocessors page.

05Self-hosted deployment

Vantage ITSM can be installed on your own servers with Docker and a local PostgreSQL database. It sends no telemetry to OpsMeld. Optional integrations, such as AI email triage, make outbound calls only if your administrator configures them, so the product can run in an isolated network.

Expense Agent can also be self-hosted. Self-hosted covers your database, storage, and credentials. AI interpretation, Business Central sync, and Teams notifications still call out to their respective providers’ cloud APIs.

06AI features

AI output is presented as a suggestion for a person to confirm. Expense Agent never posts to Business Central without an approval, and Vantage’s AI email triage is off unless enabled. Customer content is not used to train general-purpose models.

07Incident response

If we become aware of a security incident affecting customer data, we will investigate, contain it, and notify affected customers without undue delay, including the information they need to meet their own obligations under the DPDP Act and other applicable law.

08Responsible disclosure

If you believe you have found a vulnerability in any OpsMeld product or website, email security@opsmeld.com with steps to reproduce and the impact you observed.

  • We will acknowledge your report within 2 business days and keep you updated until it is resolved.
  • Test only against accounts and workspaces you own or have permission to use.
  • Do not access, change, or delete other customers’ data, and do not degrade service for others.
  • Give us reasonable time to fix the issue before disclosing it publicly.

We will not pursue legal action against research carried out in good faith under these rules. Our security.txt file lists the same contact.