Transparency
Information security
Whoever looks after the security of your environment has to be secure first. OpsGIS works inside your server, so we treat every part of the platform as a security component.
On your server
- No open ports. OpsGIS only makes outbound connections; nobody gets into your server through it.
- Nothing runs without our signature. The installed component only accepts updates and commands authenticated by AlphaOps.
- You choose the mode: observe only, or observe and act, and which actions.
- Lightweight: limited CPU and memory use, so it never competes with ArcGIS.
Communication with the platform
- Each machine has its own identity, and all communication is authenticated and encrypted.
- Tampered, replayed or late messages are rejected.
- The rules you set cannot be changed in transit, and undoing an action is checked first.
Data and isolation
- One database per customer, separate from all others, hosted in Brazil.
- Separation by company and by machine enforced by the database itself, not just the screen.
- Encrypted passwords and keys, never shown again once saved.
- Encryption in transit and at rest.
- We collect the minimum needed and filter at the source.
Access
- No password to leak: sign in with a one-time code or your organization's Microsoft account.
- Fine-grained permissions by company, environment and machine, from view only to install.
- Support only with your authorization, time-limited, automatically closed and recorded.
- Restricted internal access with two-factor authentication.
Audit and evidence
- A trail that cannot be erased of OpsGIS actions, changes and access.
- History protected against deletion.
- Signed evidence, ready for audit, that can be verified without depending on us.
How we build
- Automated security tests on every release.
- Every release goes to a test group first, with one-click rollback.
- Dependencies checked against known vulnerabilities.
- Artificial intelligence protected against malicious instructions hidden in the data.
- Least privilege: each part accesses only what it needs.
If something happens
We investigate every security incident that may affect customer data. If there is relevant risk or harm, we notify the affected customers with what happened, what was affected and what we did, and we notify the Brazilian Data Protection Authority (ANPD) when the law requires it.
Found a flaw?
We thank everyone who reports responsibly. Write to contato@alphaops.com.br with the subject "Security", describing how to reproduce it. Do not access data that is not yours, do not degrade the service, and give us reasonable time to fix it before disclosing. Our contact is also in security.txt.