Opal Security · Trust Center
Opal Security Trust Center
Trust center
Opal Security maintains a public trust center covering its security and compliance posture.
CompanyCybersecurityAccess ManagementIdentity and Access ManagementLeast PrivilegeAccess ReviewsSecurity
Certifications & Compliance
Source
Trust Center
generated: '2026-07-20'
method: searched
source: https://opal.dev/security
provider: Opal Security
legal_entity: Perma Security, Inc. (dba Opal)
trust_center:
url: https://opal.dev/security
name: Trust Center
last_updated: '2025-06-05'
compliance:
- name: SOC 2
status: documented
detail: >-
The Trust Center describes SOC 2 as the auditing procedure Opal follows;
an independent third-party penetration test is performed at least annually.
- name: GDPR
status: documented
- name: CCPA
status: documented
security_measures:
- Personnel security awareness training and confidentiality agreements.
- Two-factor authentication gating production data access; time-bound, on-call event-bound elevated access; periodic access reviews.
- Encryption in transit (TLS 1.2+ / VPN) and at rest (AWS KMS), including database backups.
- Automated alerting and searchable audit logging of access-change events; internal Opal employee actions logged.
- Daily encrypted database backups (AWS KMS) for the cloud offering.
- Secure SDLC — third-party automated security testing pre-release, peer-reviewed production releases.
- Intrusion prevention/detection monitoring; documented incident response plan.
- Vulnerability management program with monthly internal scans and >= annual third-party penetration testing.
subprocessors:
- name: Amazon Web Services (AWS)
purpose: Hosting and cloud infrastructure
region: USA
- name: Auth0
purpose: Developer user identity platform
region: USA
- name: LaunchDarkly
purpose: Feature release management
region: USA
- name: Anthropic
purpose: LLM API for remediation recommendations, request feedback, taxonomy suggestions
region: USA
contacts:
security: security@opal.dev
subprocessors: subprocessors@opal.dev
documents:
privacy_policy: https://opal.dev/privacy-policy
terms_of_service: https://opal.dev/terms-of-service
saas_agreement: https://opal.dev/saas-agreement
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/opal-security-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.