Security & trust
Transparency noticeCustomer-Facing Security Overview
A factual, non-certification overview of defense-in-depth, tenant-scoped, replay-safe security controls.
V10EN
01
1. Security position
Nightvault designs OperalonOS around defense in depth, tenant-scoped authorization, least privilege, secure authentication, protected integration boundaries, signed provider events, replay and idempotency controls, bounded requests, untrusted-content isolation, security evidence, and controlled release procedures.
02
2. Control design
- Workspace-scoped authentication and authorization using server-derived tenant context.
- Database row-level and tenant-isolation controls for Customer records.
- MFA or equivalent step-up controls for designated privileged actions.
- Encryption in transit and protected handling of selected secrets and governed content.
- Signed webhook validation, replay prevention, idempotency, and reconciliation for high-risk provider and billing events.
- Bounded requests, rate controls, origin and content-type validation, security headers, and isolation of untrusted content.
- Privacy-minimized security evidence and controlled operational access.
- Secure development, forward-only migrations, staged rollout, rollback, and evidence-preservation procedures.
03
3. Customer responsibilities
- Select appropriate administrators and promptly remove access that is no longer required.
- Apply least privilege and use available MFA.
- Manage connected-provider permissions and endpoint security.
- Review AI Output and higher-risk external actions.
- Protect exported data and promptly report suspected unauthorized access to security@operalonos.com.