Trust & Security

Architecture & Security FAQ

Straight answers for the security and procurement teams evaluating OpsAlign — where your data lives, how it's isolated, and how we handle incidents.

Last updated 2026-08-29

Where does our data live?

All assessment data lives in a dedicated Supabase (PostgreSQL) instance, hosted on AWS infrastructure. Every table enforces row-level security scoped to your organization's tenant ID — other tenants' data isn't just hidden by the UI, it's unreachable at the database query level regardless of which application code runs the query.

Where does the computation happen?

Scoring, risk-dollar quantification, and compliance-readiness calculations run as PostgreSQL functions inside Supabase, server-side, never in the browser. The application layer (Vercel serverless functions) orchestrates these calls and handles report generation; it doesn't reimplement scoring logic client-side.

Is our data used to train AI models?

No. Assessment narratives and report generation call the Claude API (Anthropic) for analysis and drafting. Under Anthropic's standard commercial API terms, retained data is never used for model training without express permission — this is the default policy for API customers generally, not something that requires a special agreement. We can provide the specific data processing terms on request.

What's your infrastructure stack?

Vercel (application hosting, edge network, serverless compute), Supabase/AWS (database), SendGrid (email delivery), Stripe (payment processing — PCI compliance is handled by Stripe directly, we never touch raw card data). No self-managed servers; no OS-level patching surface, since everything runs on managed platforms.

How is our data isolated from other clients?

Multi-tenant row-level security (RLS) at the database layer, not application-layer filtering. Every table that holds client data has a Postgres policy tying rows to tenant membership — this is enforced by the database itself, independent of which part of the application is asking.

Who at ITOMAC can access our data, and how do you control that?

Access is role-based and scoped to tenant membership, with distinct admin and read-only roles enforced at the database level, not just the UI. ITOMAC staff access is itself gated through the same tenant-membership model, so a support or admin role only reaches what that role is entitled to see, by database policy rather than by what the interface happens to show.

Do you have SOC 2 / ISO 27001?

Not yet certified. We're evaluating SOC 2 readiness and haven't committed to a certification date. Happy to walk through our current control set in the interim.

What's your incident response / breach notification process?

We maintain a written incident response plan covering severity triage, containment steps, and notification procedures for a security or data event. Details are available as part of a security review on request.

How do you handle backups and disaster recovery?

Supabase provides automated daily backups with 7-day retention on our plan tier. Application code and infrastructure configuration are version-controlled in GitHub, with all changes deployed through Vercel's build pipeline — so the full application state is reproducible from source control independent of any single server.