Trust · Security
Built to be quiet about your data
The shorter version: encrypted in transit, encrypted at rest, masked at the boundary, and never used to train anything.
Encryption
- TLS 1.3 for all data in transit.
- AES-256 encryption at rest.
- Encrypted, regionally-segregated backups.
Infrastructure
- SOC 2 Type II compliant hosting.
- Isolated tenant environments per organisation.
- Quarterly third-party security audits.
- Always-on DDoS protection at the edge.
Privacy controls
- Automatic PII masking in session recordings.
- Configurable data retention windows.
- Element-level masking for sensitive UI.
- Network request filtering at the SDK boundary.
Access control
- Role-based access control across the organisation.
- SSO integration on Team plans (SAML, OIDC).
- Audit logs for every action that touches data.
- API key rotation and scoped tokens.
Report a vulnerability
Found something? Send the details and a way to reach you to security@optics-qa.com. We acknowledge within 48 hours and credit responsible reporters in our changelog.