Trust Center

Security and compliance, by default.

Opal is the operating layer for AI inside regulated enterprises. Security, privacy, and governance are not features — they are how the platform is built.

Programs & certifications
SOC 2 Type II

Annually audited controls covering security, availability, and confidentiality.

ISO 27001

Information security management system certified to ISO/IEC 27001.

GDPR & CCPA

DPA, SCCs, and data subject rights workflows for EU and California residents.

Encryption

TLS 1.2+ in transit, AES-256 at rest, customer-managed keys on Enterprise.

Identity

SAML SSO, SCIM provisioning, fine-grained RBAC, and audit logging.

Reliability

Multi-region architecture with 99.9% uptime SLA on Enterprise plans.

Request documents

Pen tests, SOC 2 reports, DPAs, and the subprocessor list.

Security questionnaires, third-party audit reports, our Data Processing Addendum, and our current subprocessor list are available to customers and prospects under NDA.

Report a vulnerability

We welcome reports from security researchers. Please send details, reproduction steps, and your contact info to security@deployopal.com. We will acknowledge within two business days.

For privacy questions, see our Privacy Policy.