The answers your IT team asks for, before they ask.
Identity, access, auditability and where your data physically sits. Written so a security reviewer can work through it in one pass.
Single sign-on, with provisioning.
Operify AI federates to your identity provider rather than becoming another password for your workforce to lose.
Single sign-on
Your existing identity provider authenticates the user. Sign-in policy, MFA and conditional access stay where your security team already manages them.
SCIM provisioning
Accounts are created, updated and deactivated from your directory. A leaver removed there loses access here, which is the control that matters most on a workforce with real turnover.
Verified domains
Domains are verified before they can be used for federated sign-in, so nobody can attach an account to your organisation by claiming an address.
Frontline sign-in
Operatives who have no corporate identity sign in with an email, username or payroll number. The same account model, without forcing directory accounts on a thousand cleaners.
Capabilities, not job titles.
Permissions are granted as named capabilities and grouped into roles, so access is described by what a person can do rather than by what they are called.
The permission matrix
Every capability is listed and assignable. A duty manager can be given live operations without being given payroll data, and the grant is visible rather than implied.
Enforced, not hidden
A missing capability blocks the screen rather than dimming a button. Someone without operations.live.view is told what they lack and who can grant it.
Organisation scoping
Data is scoped to your organisation, its departments and sites. Access follows the org structure you configure, not a flat list of users.
Who changed what, when.
Operations software is evidence. If a record can be changed without a trace, the evidence is worthless in the disputes it exists to settle.
Audit log
Changes are recorded with the actor and the time. This is the log you reach for when a client disputes a timesheet or an incident record.
Evidence at the point of work
Clock-ins, checkpoint scans, signatures, photographs and form submissions are captured when the work happens and timestamped, rather than typed up afterwards.
Versioned documents
Method statements and certifications carry versions and expiry, so a signature is against a specific version rather than a document that has since changed.
Where it sits, and who processes it.
Hosted in the European Union
Service data and uploaded files are hosted in the EU. The one exception is the AI assistant in the administrative console, which is set out below and in full on the sub-processors page.
Encrypted in transit
Everything moves over HTTPS. Passwords are stored hashed and are never held in plaintext.
Restricted access
Production access is limited to the people who need it. Administrative accounts are created deliberately rather than by open sign-up.
Named sub-processors
Cloud hosting and database, file and object storage, email delivery, error monitoring, product analytics and AI processing. Each is listed with its purpose and processing location.
Deletion that happens
An operative can request deletion from the app and it is actioned within 30 days. What is deleted, and what your organisation may be legally required to keep, is written out rather than summarised.
Registered, and independently assessed.
ICO registration ZB905842
Registered with the Information Commissioner's Office as a data controller. Verifiable on the ICO public register.
Data Processing Agreement
Available so you can appoint Operify AI as a processor, with the sub-processor list forming part of it.
ISO 27001, in progress
The information security management system is being implemented with Sprinto, ahead of an independent audit through a certification body accredited by the International Accreditation Forum.
Certifications
Where we stand on the three a procurement team asks for. Full detail, including our ICO registration, is on the trust and compliance page.
ISO/IEC 27001
2022 revision
UK GDPR
Data Protection Act 2018
EU GDPR
Regulation 2016/679
Security questions, and disclosure
Send security questionnaires, DPA requests and vulnerability reports to the address below. If you believe you have found a vulnerability, tell us before you tell anyone else and we will work it with you.
Sub-processorsTrust and complianceMobile app and platform privacy policy
Bring us your security questionnaire.
We would rather answer it before the commercial conversation than after it.