Initializing Operalta...

Operalta

Resources / Security

Security at Operalta

Each person sees only what their access allows. Agents follow the same rules. The platform records every change.

Back to resources

Access

Set per person

Only internal members with company-wide access see the whole company.

Agents

Same rules as people

Access is checked each time an agent uses a tool.

Audit

Written by the platform

No workspace can edit or delete an audit entry.

A tower on a hill, reached by a single stair

How it works

How your work is protected

Roles and access scope

Every member has a role, an access scope and a member kind. Only internal members with company-wide access see the whole company.

Partners see what you share

You can give a partner access to one Room, or to your published outputs only. You can revoke that access at any time.

Agents follow your permissions

Access is checked when an agent calls a tool, not only when a page loads. If a membership cannot be confirmed, the person is treated as external. The MCP server and the CLI use the same permissions as the app.

An audit trail you can export

Only the platform writes audit entries. No workspace can edit or delete one. Admins read and export the trail in Settings → Audit trail.

Credits you control

Agent runs draw on a prepaid credit balance. Admins manage that balance.

Your data stays in Europe

Your data is stored in one European region, in Zurich, Switzerland. It is encrypted in transit and at rest. It is not used to train third-party models.

Generated content is sanitized

Generated HTML and markdown are sanitized before they render. An HTML document opens in a sandboxed frame that cannot run scripts or read your cookies.

Every failed request is traceable

When a request fails, the error carries a request ID. Our server logs record the same ID, so we can find what went wrong.

Your privacy rights

Under GDPR and CCPA, you can ask to see, correct, export or delete your personal data. We do not sell personal information.

Related pages

Read the details

Security terms

Our security controls, in contract language.

Open the security terms

Privacy policy

How we collect, store and delete personal data.

Open the privacy policy

Sub-processors

The providers that process data on our behalf.

Open the list

Developer docs

How the API, the CLI and the MCP server authenticate.

Open the docs

Need more than the overview?

Use this page when trust review starts and the product map is already clear

This page is the short trust layer for access, privacy, and operational posture. If you need formal detail, use Security Terms or contact security@operalta.com.

Back to resources