Straight answers for your security review.
Performance review data is among the most sensitive data your company holds. This page says plainly how we protect it — and where a formal document exists, we'll send it: request the DPA or a security review.
Encryption
All traffic is encrypted in transit with TLS 1.2+, and all customer data is encrypted at rest with AES-256. White-label subdomains are served with automatically provisioned certificates.
AI and model training
We never train AI models on customer data — on any plan, under any setting. OP Intelligence uses your data only to answer the request in front of it. Every AI query is read-only, scoped to the permissions of the person asking, and logged to the admin audit trail. The same scoping applies when you connect your own model over MCP.
Access control and audit
Role-based permissions throughout, with manager notes private by default. SAML SSO is included on Scale and Plus plans; SCIM provisioning and HRIS-driven deprovisioning are available on Enterprise. Every administrative and AI action lands in an append-only audit trail that admins can review and export.
Data residency
Managed-cloud data is hosted in the United States by default. Organizations with residency requirements can arrange region selection or full on-premises / private-cloud deployment through an Enterprise agreement — including air-gapped installs where data never leaves your network.
Retention and export
Your review record is yours. Full export of reviews, notes, goals, and sign-offs as PDF and Excel at any time, at no charge. On termination, we delete customer data from production systems within 30 days and from backups within 90, and we will confirm deletion in writing on request.
Backups and availability
Nightly encrypted backups with point-in-time recovery, targeting 99.9% availability on managed cloud. Enterprise agreements carry a contractual SLA.
Sub-processors
We keep the list of sub-processors deliberately short — infrastructure hosting, email delivery, and payments — and provide the current list, with each vendor’s role, as part of the DPA. We notify DPA holders before adding or changing a sub-processor.
DPA and security review
A Data Processing Agreement is available for any paid plan — ask and we’ll send it. For deals that need a security questionnaire, we answer it ourselves, typically within five business days, and we’ll get on a call with your security reviewer directly. Formal certification (SOC 2 Type II) is in progress; we’ll publish the report here when it completes, and we’ll share our current controls documentation under NDA in the meantime.
Running a security review? Send us the questionnaire — we answer it ourselves, and a real person replies within one business day.
Contact usLast updated August 26, 2026. Questions about anything on this page: contact us.