Security

How we keep your business safe.

Security at Operator AI is not a checklist. It is how the product is built: humans stay in control, access is limited, and every action is visible.

Security principles

Control first. Transparency always.

Six principles shape how we design, operate, and support your AI roles.

Built-in approval gates

Operator never acts on its own for anything that matters. You decide which actions need a human yes, and Operator stops and asks before it proceeds.

Scoped access per tool

We connect each tool with the minimum permissions needed. No broad account takeovers. Tokens are revocable and stored encrypted at rest.

Full visibility, every action

Every decision, every message and every tool action is logged with reasoning. You can see what happened, why it happened, and roll it back if needed.

Your data is not training data

We do not use your customer data, conversations, or business context to train foundation models. Your workflows stay yours.

Encrypted in transit and at rest

All traffic is protected with TLS 1.2+. Backed data is encrypted at rest. We use short-lived tokens and rotate keys as part of regular maintenance.

Human oversight by default

New workflows start with approval on everything. You loosen the leash per process as trust builds — never the other way around.

What we do

Practices, not promises.

Security is a daily practice. Here is how we put the principles into action.

Least-privilege integrations

  • Each tool gets only the permissions required for its role.
  • OAuth tokens are scoped and never shared across customers.
  • Integrations can be paused or disconnected in one click.

Clear data boundaries

  • Customer workspaces are logically separated.
  • Context from one business is not used for another.
  • Retention periods are agreed during onboarding and configurable.

Reliable infrastructure

  • Hosted on a managed cloud provider with regional redundancy.
  • Regular backups and environment separation.
  • Monitoring and alerting for unusual activity or failures.

Contact

Talk to us about security.

We answer questions, review concerns, and take vulnerability reports seriously.

Questions about security?

Email us at security@operatorai.dev and we will respond as soon as possible.

Contact security team

Report a vulnerability

Found something we should know? We review every report and move quickly to fix real issues.

Report a vulnerability