Opisense
Trust center

How Opisense keeps your data secure and compliant

Built for security, legal, and procurement teams.

Centralized security, privacy, and compliance information in one place — with clear links to policies, registers, and deeper technical detail.

At a glance

Compliance status

Compliance status
FrameworkStatus
Compliant
Compliant
In progress
Planned
Planned
Planned
Planned

Statuses reflect our roadmap as of this page revision. Documentation is updated when milestones complete.

Where to start

Questionnaires & due diligence

Use the contact form for vendor security questionnaires and custom requests. We share what we can at the current maturity of our program.

Agreements, DPA & policies

Customer agreements, product terms, and archived legal documents live in the legal hub. Zero-retention and enterprise-specific terms are addressed in contracts where applicable.

Program overview

Opisense is building a security and compliance program aligned with leading standards such as SOC 2 and ISO 27001, with strong emphasis on privacy and transparent communication with customers.

  • Centralized security ownership and incident process
  • Secure-by-default infrastructure and deployment pipeline
  • Privacy-by-design principles across products
  • Documented internal procedures and training

Resources

Audit reports

  • Future SOC 2 Type 2 report
  • ISO certification reports

Legal

  • Customer Agreements
  • Policies & product terms
  • Legal archive

Data & privacy

Data supported

Types of data that can be processed and stored in Opisense.

  • Customer personally identifiable information (PII)
  • Employee personally identifiable information (PII)
  • Financial and billing information

Overview of how we handle customer data, apply GDPR principles, and document retention.

  • Data retention processes established
  • Data classification policy in place
  • No customer data shared with advertising networks

Subprocessors

Current register · v1 · 3 March 2026

The table below reflects the “Current sub-processors” section of the Subprocessor Register v1 (last updated 3 March 2026). When we add or change sub-processors, we update the PDF and this page together.

The signed PDF remains the authoritative source. Open the register at /subprocessors.

Subprocessors
Sub-processorProcessing purposeData categoriesHosting locationSafeguards
Amazon Web Services (AWS)Cloud infrastructure and hostingAll Customer Data categoriesFrankfurt, Germany (EU)GDPR-compliant DPA, SCCs where applicable
ClerkAuthentication and user managementUser credentials, session dataUSA with EU presenceSCCs, EU-US DPF
StripePayment processingBilling and payment dataEU and USASCCs, EU-US DPF, PCI DSS certified
ElevenlabsSpeech-to-text and text-to-speech processingVoice data, contentUSASCCs, EU-US DPF, zero-retention API
OpenAIAI model inference for content generation, analysis and automationUser input, content data, AI-generated outputUSASCCs, EU-US DPF, zero-retention API
AnthropicAI model inference for content generation, analysis and automationUser input, content data, AI-generated outputUSASCCs, EU-US DPF, zero-retention API
VercelApplication hosting and edge deliveryRequest metadata, IP addressesUSASCCs, EU-US DPF
ConvexBackend database and real-time data infrastructureApplication data, user data, content dataUSASCCs, EU-US DPF
RagieRetrieval-augmented generation (RAG) infrastructureCustomer documents, indexed contentUSASCCs, EU-US DPF
RecallMeeting recording and transcription captureMeeting audio, transcriptions, participant dataUSASCCs, EU-US DPF
ComposioIntegration orchestration platformIntegration data, user identifiers, workflow metadataUSASCCs, EU-US DPF
ResendTransactional email deliveryEmail addresses, email contentUSASCCs, EU-US DPF
AxiomLogging and observabilityPlatform logs, request metadata, user identifiersUSASCCs, EU-US DPF

Controls

FAQ

Common questions from security, legal, and procurement teams.

Further questions? Contact us via our contact form.

Updates

This page will be updated as we reach new milestones in our compliance roadmap and publish new documentation.