Workspace isolation
Enforced in the database with row-level security.
Role-based access
Five roles, with limited client portal visibility.
Encryption
HTTPS in transit, encrypted storage at rest.
Append-only audit trail
Agreement activity that cannot be edited or deleted.
Our approach
We treat every agreement, approval and payment record as confidential. Security is built into how AgreeOps stores data and decides who can see it, not added on afterwards.
This page only describes protections that exist in the product today. We would rather under-promise than overstate.
Data isolation
Every workspace's data is isolated at the database level using row-level security policies. Members of a workspace can only read the data that belongs to their own workspace.
Your clients are isolated too. A client can only read their own client record and the agreements that have been explicitly shared with them.
Roles and access
Every workspace member is assigned one of five roles.
- Owners and admins invite team members and manage their roles.
- Managers and above can invite clients and share agreements.
- Only owners and admins can delete records.
- Only owners and admins can view the audit log and manage payment provider settings.
Encryption
Data travels over HTTPS, and browsers are instructed to only connect to AgreeOps securely. Data at rest is stored with our database provider, Supabase, on encrypted storage.
Payment provider credentials receive an additional layer of protection. They are encrypted with AES-256-GCM before they are stored.
Audit trail
Activity on agreements is recorded so you can see who did what, and when. The trail is append-only: database permissions prevent it from being edited or deleted through the application.
Owners and admins can search the audit log, filter it by action and export it as CSV.
Application protections
Secure HTTP headers
Strict transport security, clickjacking protection, content-type sniffing protection, a strict referrer policy and a restrictive browser permissions policy.
Rate limiting
Payment and e-signature webhooks and the agreement sharing endpoint are rate limited to reduce abuse.
Server-side secrets
Saved payment provider secrets are never sent back to the browser. Editing them means entering them again.
Compliance and certifications
AgreeOps has not yet completed a third-party certification such as SOC 2 or ISO 27001. If that changes, we will publish it here.
If your team needs a security review or has specific requirements, email us and we will answer honestly.
