Skip to main content
PRIMEOPSBack to platform
Platform 2.0 security overview

Security claims should follow verified controls.

PrimeOps is designing the customer platform around OWASP ASVS Level 2, default-deny tenant authorization, evidence lineage, privacy minimization, and reversible release controls.

Target customer controls

Verified identity

Organization access begins only after identity and email verification.

Role-based access

Owner, administrator, manager, analyst, and viewer permissions stay explicit.

Tenant-scoped records

Every protected query and object check must be bound to an authorized organization.

Session controls

Customers can review and revoke active sessions after the identity provider is activated.

Audit history

Sensitive identity, membership, export, upload, and role events are append-oriented.

Privacy requests

Export and deletion requests follow authorization and retention controls.

Current release state

The current public release includes a synthetic portal and a deliberately closed credential gate. Provider-backed authentication, organization persistence, RLS, encrypted storage, MFA, session revocation, audit retention, backup restoration, and transactional identity email are not represented as active until their external owners and evidence are approved.

Report a concern

Send a concise security report to support@getprimeops.ai. Do not include credentials, payment data, or unnecessary personal information.