OperityHQ

OperityHQ legal

Security

Security is built into how OperityHQ authenticates users, separates workspaces, and operates connected services.

Last updated August 17, 2026

This page describes the current security baseline and does not claim a certification or audit that has not been formally completed.

Access controls and workspace isolation

OperityHQ uses authenticated access, role-based permissions, workspace boundaries, and database policies to limit access to supported features and customer information. Sensitive server operations require protected credentials that are not exposed to the browser.

Service and data protection

The service uses managed infrastructure and encrypted network connections. Access to production systems and configured providers is limited to the people and processes needed to operate and support the service.

Logging and response

Supported workflows produce operational and audit records that help investigate access, failures, and important changes. Security findings are reviewed and addressed according to their scope and risk.

Customer responsibilities

Workspace administrators should assign the least access required, remove access promptly when roles change, protect credentials, review connected integrations, and follow applicable consent and communications rules.

Report a security concern

Please report suspected vulnerabilities, unauthorized access, or unusual account activity promptly. Include enough detail for us to investigate, but do not send passwords, secret keys, or unnecessary personal information by email.

Contact

Questions about this page can be sent to frank@operityhq.com.