Verified identity
Organization access begins only after identity and email verification.
PrimeOps is designing the customer platform around OWASP ASVS Level 2, default-deny tenant authorization, evidence lineage, privacy minimization, and reversible release controls.
Organization access begins only after identity and email verification.
Owner, administrator, manager, analyst, and viewer permissions stay explicit.
Every protected query and object check must be bound to an authorized organization.
Customers can review and revoke active sessions after the identity provider is activated.
Sensitive identity, membership, export, upload, and role events are append-oriented.
Export and deletion requests follow authorization and retention controls.
The current public release includes a synthetic portal and a deliberately closed credential gate. Provider-backed authentication, organization persistence, RLS, encrypted storage, MFA, session revocation, audit retention, backup restoration, and transactional identity email are not represented as active until their external owners and evidence are approved.
Send a concise security report to support@getprimeops.ai. Do not include credentials, payment data, or unnecessary personal information.