Skip to content

Security & trust

Security information
for your review.

Understand the questions to resolve before your operation moves onto OpsUI. Start with access, follow the data, and agree the responsibilities.

Clear scope. Verifiable information.

This overview separates published product information from deployment controls that need confirmation. Content reviewed 9 September 2026; this is not a security audit or certification.

OpsUI’s role catalogue describes the work of pickers, packers, stock controllers, supervisors and other teams. Use the workflow review to check which records and actions each person should be able to access.

Published role catalogue
What to confirm for your team
  • Map roles to the records and actions people need, including administrator and support access.
  • Confirm authentication, MFA availability, session controls and the process for removing access.
  • Test permission boundaries with your actual workflows; a role description alone does not demonstrate enforced access controls.

Confirm where your production records, backups and logs are stored, who can access them and how long they are retained. Treat each of these as a separate requirement in your review.

Confirm during security review
Bring these data requirements
  • Production hosting location, backup location and subprocessors relevant to your deployment.
  • Encryption at rest and in transit, key management and access arrangements.
  • Data export, retention and deletion requirements, including what happens at the end of service.
  • AU/NZ website domains and billing currencies do not independently establish data residency.

Discuss how activity is recorded, changes are investigated and service is recovered after a problem. Ask for the scope of the controls that apply to your deployment.

Confirm during security review
Logging, recovery and incident questions
  • Which user and system actions are recorded, who can review them and the applicable retention period.
  • Backup frequency, recovery points, restore testing and agreed recovery objectives.
  • Incident ownership, escalation and customer communication arrangements.
  • Any contracted availability or support commitments. This page does not establish an uptime SLA.

Good operating controls need both product configuration and a clear process. Agree the responsibilities of OpsUI, your administrators and the systems connected to your operation.

Confirm during security review
Define the handoffs
  • Your team: joiner and leaver access, device management, approval responsibilities and operational data quality.
  • OpsUI: the service controls and support responsibilities agreed for the deployment.
  • Connected systems: account permissions, record ownership, integration credentials and error handling.

Certification and control assurance should be supported by current documentation. This page makes no SOC 2 or ISO 27001 certification claim, and does not publish a certification or MFA delivery date.

Confirm during security review
For a procurement or compliance review
  • Share the controls and evidence your procurement team needs to assess.
  • Confirm the scope, date and issuing party of any assurance document before relying on it.
  • A cloud provider’s certification does not by itself certify the OpsUI application or your deployment.

Further information

Review the existing privacy and legal information, or report a vulnerability through the published security contact.

Privacy and legal information

Report a vulnerability

Security reporting contact: security@opsui.co.nz

Your next step

Have specific security requirements?

Bring your questionnaire or procurement requirements. We’ll work through the applicable controls and the evidence needed for your review.