Security

The answers your IT team asks for, before they ask.

Identity, access, auditability and where your data physically sits. Written so a security reviewer can work through it in one pass.

Identity

Single sign-on, with provisioning.

Operify AI federates to your identity provider rather than becoming another password for your workforce to lose.

Single sign-on

Your existing identity provider authenticates the user. Sign-in policy, MFA and conditional access stay where your security team already manages them.

SCIM provisioning

Accounts are created, updated and deactivated from your directory. A leaver removed there loses access here, which is the control that matters most on a workforce with real turnover.

Verified domains

Domains are verified before they can be used for federated sign-in, so nobody can attach an account to your organisation by claiming an address.

Frontline sign-in

Operatives who have no corporate identity sign in with an email, username or payroll number. The same account model, without forcing directory accounts on a thousand cleaners.

Access

Capabilities, not job titles.

Permissions are granted as named capabilities and grouped into roles, so access is described by what a person can do rather than by what they are called.

The permission matrix

Every capability is listed and assignable. A duty manager can be given live operations without being given payroll data, and the grant is visible rather than implied.

Enforced, not hidden

A missing capability blocks the screen rather than dimming a button. Someone without operations.live.view is told what they lack and who can grant it.

Organisation scoping

Data is scoped to your organisation, its departments and sites. Access follows the org structure you configure, not a flat list of users.

Auditability

Who changed what, when.

Operations software is evidence. If a record can be changed without a trace, the evidence is worthless in the disputes it exists to settle.

Audit log

Changes are recorded with the actor and the time. This is the log you reach for when a client disputes a timesheet or an incident record.

Evidence at the point of work

Clock-ins, checkpoint scans, signatures, photographs and form submissions are captured when the work happens and timestamped, rather than typed up afterwards.

Versioned documents

Method statements and certifications carry versions and expiry, so a signature is against a specific version rather than a document that has since changed.

Your data

Where it sits, and who processes it.

Hosted in the European Union

Service data and uploaded files are hosted in the EU. The one exception is the AI assistant in the administrative console, which is set out below and in full on the sub-processors page.

Encrypted in transit

Everything moves over HTTPS. Passwords are stored hashed and are never held in plaintext.

Restricted access

Production access is limited to the people who need it. Administrative accounts are created deliberately rather than by open sign-up.

Named sub-processors

Cloud hosting and database, file and object storage, email delivery, error monitoring, product analytics and AI processing. Each is listed with its purpose and processing location.

Deletion that happens

An operative can request deletion from the app and it is actioned within 30 days. What is deleted, and what your organisation may be legally required to keep, is written out rather than summarised.

Governance

Registered, and independently assessed.

ICO registration ZB905842

Registered with the Information Commissioner's Office as a data controller. Verifiable on the ICO public register.

Data Processing Agreement

Available so you can appoint Operify AI as a processor, with the sub-processor list forming part of it.

ISO 27001, in progress

The information security management system is being implemented with Sprinto, ahead of an independent audit through a certification body accredited by the International Accreditation Forum.

Certifications

Certifications

Where we stand on the three a procurement team asks for. Full detail, including our ICO registration, is on the trust and compliance page.

ISO/IEC 27001

2022 revision

In progress

UK GDPR

Data Protection Act 2018

In progress

EU GDPR

Regulation 2016/679

In progress

Security questions, and disclosure

Send security questionnaires, DPA requests and vulnerability reports to the address below. If you believe you have found a vulnerability, tell us before you tell anyone else and we will work it with you.

hello@operifyai.co.uk

Bring us your security questionnaire.

We would rather answer it before the commercial conversation than after it.