Trust & Security

Security at AgreeOps

Agreements hold sensitive commercial terms. Here is how we protect them, and what we have not done yet.

Last updated: 30 September 20264 min readApplies to agreeops.causly.in

Workspace isolation

Enforced in the database with row-level security.

Role-based access

Five roles, with limited client portal visibility.

Encryption

HTTPS in transit, encrypted storage at rest.

Append-only audit trail

Agreement activity that cannot be edited or deleted.

01

Our approach

We treat every agreement, approval and payment record as confidential. Security is built into how AgreeOps stores data and decides who can see it, not added on afterwards.

This page only describes protections that exist in the product today. We would rather under-promise than overstate.

02

Data isolation

Every workspace's data is isolated at the database level using row-level security policies. Members of a workspace can only read the data that belongs to their own workspace.

Your clients are isolated too. A client can only read their own client record and the agreements that have been explicitly shared with them.

03

Roles and access

Every workspace member is assigned one of five roles.

OwnerAdminManagerMemberViewer
  • Owners and admins invite team members and manage their roles.
  • Managers and above can invite clients and share agreements.
  • Only owners and admins can delete records.
  • Only owners and admins can view the audit log and manage payment provider settings.
04

Encryption

Data travels over HTTPS, and browsers are instructed to only connect to AgreeOps securely. Data at rest is stored with our database provider, Supabase, on encrypted storage.

Payment provider credentials receive an additional layer of protection. They are encrypted with AES-256-GCM before they are stored.

05

Audit trail

Activity on agreements is recorded so you can see who did what, and when. The trail is append-only: database permissions prevent it from being edited or deleted through the application.

Owners and admins can search the audit log, filter it by action and export it as CSV.

06

Application protections

Secure HTTP headers

Strict transport security, clickjacking protection, content-type sniffing protection, a strict referrer policy and a restrictive browser permissions policy.

Rate limiting

Payment and e-signature webhooks and the agreement sharing endpoint are rate limited to reduce abuse.

Server-side secrets

Saved payment provider secrets are never sent back to the browser. Editing them means entering them again.

07

Compliance and certifications

AgreeOps has not yet completed a third-party certification such as SOC 2 or ISO 27001. If that changes, we will publish it here.

If your team needs a security review or has specific requirements, email us and we will answer honestly.

08

Report a vulnerability

If you believe you have found a security issue in AgreeOps, please email us with the details and steps to reproduce it. Please give us a reasonable chance to fix it before sharing it publicly.