OperityHQ legal
Security
Security is built into how OperityHQ authenticates users, separates workspaces, and operates connected services.
Last updated August 17, 2026
This page describes the current security baseline and does not claim a certification or audit that has not been formally completed.
Access controls and workspace isolation
OperityHQ uses authenticated access, role-based permissions, workspace boundaries, and database policies to limit access to supported features and customer information. Sensitive server operations require protected credentials that are not exposed to the browser.
Service and data protection
The service uses managed infrastructure and encrypted network connections. Access to production systems and configured providers is limited to the people and processes needed to operate and support the service.
Logging and response
Supported workflows produce operational and audit records that help investigate access, failures, and important changes. Security findings are reviewed and addressed according to their scope and risk.
Customer responsibilities
Workspace administrators should assign the least access required, remove access promptly when roles change, protect credentials, review connected integrations, and follow applicable consent and communications rules.
Report a security concern
Please report suspected vulnerabilities, unauthorized access, or unusual account activity promptly. Include enough detail for us to investigate, but do not send passwords, secret keys, or unnecessary personal information by email.
Contact
Questions about this page can be sent to frank@operityhq.com.
