Trust

Security at oprx.ai

oprx.ai is built by an ITSEC company. Security is the starting assumption of the architecture, not a feature added later.

Encryption

All traffic is encrypted with TLS 1.3. Data at rest is encrypted with AES-256, with key separation per tenant so no customer's data can be decrypted with another's keys.

Tenant isolation and residency

Each organisation runs against an isolated data core, pinned to the region you select — EU, UK, US or GCC — and it stays there.

Identity and access

SAML and OIDC single sign-on, SCIM provisioning and de-provisioning, and role, team and field-level permissions applied consistently across every module and every agent.

Auditability

Every read, write and agent action is recorded in a tamper-evident audit trail that you can search and export. Agents operate inside the same permission model as the humans they work for.

AI governance

Your data is never used to train shared models. Model routing, retention and the actions an agent may take without approval are configurable per organisation.

Compliance

SOC 2 Type II and ISO 27001 programmes are in progress. Penetration testing and secure development practices are run alongside ITSEC's existing security practice.

Reporting a vulnerability

Email security@oprx.ai. We acknowledge reports within one business day and will keep you updated through remediation.