Your Security is Our Top Priority
As a security-focused company, we hold ourselves to the highest standards. Learn about our security practices, certifications, and commitment to protecting your data.
Legal Entity
PlatOps Security, LLC
Headquarters
Gaithersburg, Maryland, USA
Security Practices
We implement comprehensive security controls to protect your data and systems.
Data Encryption
All data is encrypted in transit using TLS 1.3 and at rest using AES-256. We follow industry best practices for key management.
Access Control
Role-based access control (RBAC) with least-privilege principles. Multi-factor authentication required for all systems.
Continuous Monitoring
24/7 security monitoring with automated threat detection. Real-time alerting and incident response procedures.
Secure Infrastructure
Infrastructure hosted in SOC 2 compliant data centers with physical security, redundancy, and disaster recovery.
Network Security
Network segmentation, intrusion detection systems, and regular vulnerability scanning to protect against threats.
Identity Management
Enterprise identity providers with SSO integration. Strong password policies and session management.
How the Client Console Protects You
Clients follow their engagement, tickets and invoices at console.platops.com. These controls are built in, not optional.
Phishing-resistant sign-in
Passkeys, security keys or an authenticator app. Your owners can require multi-factor authentication for everyone in your organization, and PlatOps staff cannot sign in without it.
No standing access for PlatOps staff
Staff see inside your organization only when you grant access: read-only or read-write, for at most 24 hours, and you can revoke it at any time.
An audit log you can read
Member and invitation changes, product changes, access grants and every staff access session are recorded in your organization's own audit log.
Tenant isolation in the database
PostgreSQL row-level security on every organization's tables, so one client's records are never visible in another client's context.
Sessions you control
Server-side sessions you can see and end from your account. Invoices are paid on Stripe's hosted page; the console never stores card details.
No third-party scripts, known senders
The console loads no analytics, chat or tracking scripts, enforced by a strict Content Security Policy. Its emails come from no-reply@platops.io and link only to console.platops.com.
Compliance & Certifications
We maintain compliance with industry standards and regulations to ensure your data is protected.
SOC 2 Type II
Last audited 2025Annual audit of security, availability, and confidentiality controls
HIPAA
Last audited 2025Compliant practices for handling protected health information
GDPR
CompliantEuropean data protection regulation compliance
CCPA
CompliantCalifornia Consumer Privacy Act compliance
Need our SOC 2 report or other security documentation? Request access
Our Security Commitments
Beyond technical controls, we maintain organizational practices to ensure security.
Vulnerability Disclosure
We maintain a responsible vulnerability disclosure program. Security researchers can report vulnerabilities to security@platops.com.
Incident Response
Documented incident response procedures with defined escalation paths. We notify affected parties within 72 hours of confirmed breaches.
Employee Security
Background checks for all employees. Regular security awareness training and phishing simulations.
Vendor Management
Third-party vendors are assessed for security practices. Contractual requirements for data protection.
Vulnerability Disclosure
We appreciate the security research community's efforts to improve security. If you've discovered a potential security vulnerability in our systems, please report it responsibly.
How to Report
- Email your findings to security@platops.com (PGP Key)
- Include detailed steps to reproduce the issue
- Allow reasonable time for us to respond and address the issue
- Do not access, modify, or delete data belonging to others
We commit to acknowledging receipt within 48 hours and providing status updates as we investigate and remediate reported issues.
Questions About Our Security?
We're happy to discuss our security practices, provide documentation, or answer any questions about how we protect your data.
PlatOps® is a trademark of PlatOps Security, LLC. All rights reserved.