Security & tenancy

One platform. Every company's data kept apart.

OPPS Academy runs the same SOP engine, training academy, search and AI assistant for every customer — but tenant separation is a database-level guarantee, not a UI convention. This page describes exactly how, so you can evaluate it rather than take our word for it.

How isolation is enforced

What actually stops one company from seeing another's data

Isolation enforced in the database, not just the interface

Company data is separated using Postgres row-level security policies, not application-level filtering alone. A query that isn't scoped to the right company is rejected by the database itself.

Authentication and sessions

Sign-in is handled through Supabase Auth. Access is by invitation: an administrator invites a person to a specific company workspace with a specific role, rather than open self-registration into shared data.

Role-scoped by the server, not the UI

What a user can see and do is checked on the server for every request — Company Admin, Manager/Trainer and Employee each get a different, enforced set of permissions, not just a different menu.

We don't get standing access to your data

Our team does not have an open, ongoing view into any company's workspace. When support genuinely requires opening one, that access is granted for a fixed window, shown as a visible banner inside the workspace for as long as it's open, and recorded in a change log — never silent, never standing.

Roles inside your workspace

Three roles, each scoped and enforced on the server

Employee

Sees only the categories, procedures, forms and training their role has been granted inside your company's workspace — enforced on the server, not just hidden in a menu.

Manager / Trainer

Assigns and reviews training and forms for the people they're responsible for, within your company's own permission structure.

Company Admin

Manages your company's users, roles, categories, branding and content. Cannot see or act on any other company's workspace.

Traceability

Every transformed page links back to its source

Procedures, training modules, forms and checklists are all generated from an uploaded document, and each one keeps a visible link to that original file. If you need to verify what the platform is telling an employee, you can always open the source it came from.

On accuracy: the platform does not fabricate policies or fill in steps a source document doesn't contain. Where information is missing from the material you provided, the affected page says so instead of inventing an answer — the same standard applies to the AI assistant.

We describe our security practices in terms of what is actually implemented today. If you have a specific compliance, hosting or data-residency requirement, ask us directly on our contact page — we'll give you a direct answer rather than a marketing one.

Have a specific security question?

Ask us before you commit your documents — we'd rather answer it upfront.