Security
Your team's data, secure and private.
MyOps holds the numbers a real estate business runs on. Here is how they are protected.
Infrastructure
Enforced in the database, not just the app.
MyOps runs on Microsoft Azure in the United States. Separation between teams is enforced in the database itself, beneath the application, so a bug in our code cannot hand one team another team’s records.
Team separation enforced by the database
Every table holding customer records is protected by PostgreSQL row-level security. A query made in one team’s session cannot return another team’s rows, even if the application asks for them. An automated check alerts us if any table drifts out of that protection.
Hosted in the United States
Your data is stored and processed on Microsoft Azure, in US data centers.
Encrypted in transit and at rest
TLS on every connection, and encryption at rest for the database and stored documents.
Nothing ships untested
Every change goes through a release process with a required automated test gate before it can reach production.
Automated backups
The production database is backed up automatically, with point-in-time restore.
Error reporting that does not leak
Crash reports are scrubbed of personal information and credentials before they leave the application.
AI
Your business is not training anybody’s model.
Maria runs on third-party AI providers. We train no model of our own, our providers are barred from training on what we send them, and turning AI off stops the data at the source.
No model training, on either side
We do not train, fine-tune, or build any model on your content, and we never sell it or share it for training. Our AI providers are prohibited from training on it, and we keep the data controls in our provider accounts locked down to match.
Off means off
AI can be switched off for your whole team, or for individual roles. When it is off, we stop sending that team’s records to any AI provider. Ask us and we apply it.
Answers stay inside your team
The assistant queries your team’s data and nothing else, protected by the same database-level separation as the rest of the platform.
Documents are deleted after reading
A document you attach is sent to the provider for that single request and deleted immediately after it finishes.
Voice notes are not retained
Recordings sent for transcription are not retained by the provider.
Vault credentials never leave
Password vault entries are indexed by their labels only. The stored password and its notes are never sent to an AI provider.
Providers named, and kept current
The AI providers we use are named, with links to their terms, in the service provider list in our privacy policy.
What providers keep, plainly
Content sent to an AI provider is held by them for up to 30 days for abuse monitoring, then deleted. We do not yet have a zero-retention arrangement, so we do not claim one.
Access
The fewest people, with the least access.
Who sees what inside a team is a business decision, so the controls sit with the business owner.
Role-based permissions
Owners, admins, and agents see different things. Financial detail and administrative settings are scoped by role.
AI controls by team and by role
AI can be enabled or disabled for the whole team, and separately for owners, admins, and agents.
Encrypted password vault
Shared team credentials are stored encrypted, and every reveal is recorded against the person who did it.
Activity logging
Sign-ins, access, and record changes are logged, so there is a trail behind who did what.
Your data stays yours
Request a copy of your data, or its deletion, at any time. What we collect and how long we keep it is written out in the privacy policy.
Have a security review to run?
Send us the questionnaire. We answer it ourselves, in writing, and we will tell you where the answer is no. Write to privacy@myops.ai.