Security
Opsonance is a runtime security product, so we hold ourselves to the same standard we ask customers to trust us with.
Reporting a vulnerability
If you believe you've found a security issue in this website or in the Opsonance platform, we want to hear from it before anyone else does. Email security@opsonance.com with a description and, if you have one, steps to reproduce it. We aim to acknowledge reports within two business days.
Please report privately and give us a reasonable window to fix an issue before disclosing it publicly. We won't pursue legal action against good-faith research conducted under this policy.
How we build
- Access to production systems is limited and audited
- Secrets and credentials are never committed to source control
- Dependencies and infrastructure are patched on a regular cadence
- Changes go through code review before shipping
Platform security
Detailed information about how the Opsonance sentinel and control plane are secured — deployment isolation, data-in-transit and at-rest handling, and our approach to least-privilege eBPF access — will be published here as the product approaches general availability.