Security

Your data, your rules.

This page only describes what the product actually does today. No certification or hosting claim appears here until it is verified.

  • Workspace isolation

    Every record belongs to a workspace. Requests without a workspace context are rejected server-side (fail-closed); one team's data is never visible to another.

  • Role and permission-based access

    Besides the CTO, Department Manager, Team Lead, PM/Quality, Member and Viewer system roles, you can define custom roles. Access comes from the permissions on the workspace membership, not the role name.

  • Audit log

    Important changes are recorded with who, what and when. Retention depends on your plan: Free 7 days, Pro 90 days, Ultra 1 year; tailored on Custom. Expired entries are purged daily.

  • Encrypted credentials

    Credentials for the Git providers you connect are stored encrypted with AES-256-GCM.

  • Signed integrations

    Outbound webhooks are signed with HMAC-SHA256. Tokens issued to external coding agents can never exceed their owner's permissions.

AI and your data

  • AI is included in OpsQI; we provide and operate the model — no keys or infrastructure for you to manage.
  • Analysis, summarisation, code review and document search run on AI infrastructure managed by OpsQI.
  • AI only works with your own workspace's data and within the user's permissions.
  • AI features unlock by plan; the monthly AI request limit is listed in the plan comparison. The sub-processor list is available on request.

KVKK (Turkish data protection law)

Role-based access, audit logs and retention periods are designed to support your own KVKK/GDPR processes as data controller. Contact us for the privacy notice, data processing agreement and sub-processor list.

Contact us