Skip to main content
Security & Trust

Your Security is Our Top Priority

As a security-focused company, we hold ourselves to the highest standards. Learn about our security practices, certifications, and commitment to protecting your data.

Legal Entity

PlatOps Security, LLC

Headquarters

Gaithersburg, Maryland, USA

Security Practices

We implement comprehensive security controls to protect your data and systems.

Data Encryption

All data is encrypted in transit using TLS 1.3 and at rest using AES-256. We follow industry best practices for key management.

Access Control

Role-based access control (RBAC) with least-privilege principles. Multi-factor authentication required for all systems.

Continuous Monitoring

24/7 security monitoring with automated threat detection. Real-time alerting and incident response procedures.

Secure Infrastructure

Infrastructure hosted in SOC 2 compliant data centers with physical security, redundancy, and disaster recovery.

Network Security

Network segmentation, intrusion detection systems, and regular vulnerability scanning to protect against threats.

Identity Management

Enterprise identity providers with SSO integration. Strong password policies and session management.

How the Client Console Protects You

Clients follow their engagement, tickets and invoices at console.platops.com. These controls are built in, not optional.

Phishing-resistant sign-in

Passkeys, security keys or an authenticator app. Your owners can require multi-factor authentication for everyone in your organization, and PlatOps staff cannot sign in without it.

No standing access for PlatOps staff

Staff see inside your organization only when you grant access: read-only or read-write, for at most 24 hours, and you can revoke it at any time.

An audit log you can read

Member and invitation changes, product changes, access grants and every staff access session are recorded in your organization's own audit log.

Tenant isolation in the database

PostgreSQL row-level security on every organization's tables, so one client's records are never visible in another client's context.

Sessions you control

Server-side sessions you can see and end from your account. Invoices are paid on Stripe's hosted page; the console never stores card details.

No third-party scripts, known senders

The console loads no analytics, chat or tracking scripts, enforced by a strict Content Security Policy. Its emails come from no-reply@platops.io and link only to console.platops.com.

Compliance & Certifications

We maintain compliance with industry standards and regulations to ensure your data is protected.

SOC 2 Type II

Last audited 2025

Annual audit of security, availability, and confidentiality controls

HIPAA

Last audited 2025

Compliant practices for handling protected health information

GDPR

Compliant

European data protection regulation compliance

CCPA

Compliant

California Consumer Privacy Act compliance

Need our SOC 2 report or other security documentation? Request access

Our Security Commitments

Beyond technical controls, we maintain organizational practices to ensure security.

Vulnerability Disclosure

We maintain a responsible vulnerability disclosure program. Security researchers can report vulnerabilities to security@platops.com.

Incident Response

Documented incident response procedures with defined escalation paths. We notify affected parties within 72 hours of confirmed breaches.

Employee Security

Background checks for all employees. Regular security awareness training and phishing simulations.

Vendor Management

Third-party vendors are assessed for security practices. Contractual requirements for data protection.

Vulnerability Disclosure

We appreciate the security research community's efforts to improve security. If you've discovered a potential security vulnerability in our systems, please report it responsibly.

How to Report

  • Email your findings to security@platops.com (PGP Key)
  • Include detailed steps to reproduce the issue
  • Allow reasonable time for us to respond and address the issue
  • Do not access, modify, or delete data belonging to others

We commit to acknowledging receipt within 48 hours and providing status updates as we investigate and remediate reported issues.

Questions About Our Security?

We're happy to discuss our security practices, provide documentation, or answer any questions about how we protect your data.

PlatOps® is a trademark of PlatOps Security, LLC. All rights reserved.