Security · access · responsible automation

Minimum necessary access.
Maximum practical clarity.

This page explains the operating practices around your Opsionic workspace. It does not claim certifications or guarantees that have not been independently established.

Private client workspaceNo secrets requested through ordinary emailHuman approval for consequential actions
Core principles

A safer workflow starts with clear boundaries.

01

Private environment

Automation Hosting is provisioned as a private client environment with its own address and login. Your dashboard identifies when that workspace has passed the final manual readiness step.

02

Least access needed

Access should be limited to the apps, permissions, and duration required for the agreed work. Broader permissions are not a substitute for proper scoping.

03

Secrets stay out of email

Passwords, API keys, tokens, and secret credentials should not be placed in normal email or dashboard request text. Secure access is arranged separately when needed.

04

Test before cutover

New workflows and migrations are built and tested separately where practical. The existing workflow remains available until validation and an agreed switch.

05

Human control where consequences matter

High-impact actions—payments, deletions, access changes, and sensitive outbound communication—should retain explicit review or approval.

06

Ownership and portability

Clients retain access to and can export their workflows. Third-party applications remain governed by their own accounts, terms, permissions, and retention practices.

Shared responsibility

What Opsionic handles—and what still needs your control.

Opsionic operating responsibility

  • Provision the agreed private environment
  • Apply platform care, updates, backups, and environment monitoring according to the purchased plan
  • Use only the access needed for agreed work
  • Document and test delivered workflows within written scope
  • Provide a human support and escalation route

Client responsibility

  • Protect account credentials and enable strong authentication where available
  • Authorize only appropriate data, apps, and business actions
  • Review high-impact decisions and regulatory obligations
  • Tell Opsionic when staff, permissions, vendors, or business rules change
  • Maintain lawful rights to the data processed by connected services
Data protection documents

The documents clients and privacy teams usually need.

These company-wide documents are maintained centrally on opsionic.com so the current version applies consistently across the main site, this automation portal, and client workspaces.

Before access is shared

A five-point client checklist.

  1. 1

    Confirm the exact apps, workflow, and outcome in scope.

  2. 2

    Use a dedicated service account where the connected app supports it.

  3. 3

    Grant the minimum role or permissions needed.

  4. 4

    Remove unnecessary real customer data from test examples.

  5. 5

    Rotate or revoke temporary access after the agreed work when appropriate.

Important distinctions

Know what each protection does.

Does “all systems operational” guarantee every business outcome?

No. The green dashboard state confirms the Opsionic environment and manually recorded service state. A third-party app, credential, field name, or business rule can still change. Workflow Assurance adds recurring functional review for critical workflows.

Are third-party apps covered by Opsionic security practices?

Connected tools remain controlled by their own providers and your account configuration. Their security, data processing, availability, and retention terms must be assessed separately.

How should a suspected incident be reported?

Email support@opsionic.com with “Security incident” in the subject. Include the affected account, approximate time, and a safe description. Do not include passwords, tokens, or sensitive data.

Can Opsionic sign custom security or data-processing terms?

Requirements must be reviewed before purchase because they can materially change architecture, scope, price, and delivery. Send the requirement for a written fit decision.

Need a written answer?

Send the exact requirement before you commit.

Security, compliance, retention, data-location, and contractual requirements should be confirmed in writing during qualification.