Security
Your data stays yours.
Operelio handles spreadsheets that contain real customer records, pipeline numbers, and contact details. Every part of the platform is built around that responsibility.
Last updated May 2026
Encryption
Encrypted at every stage
Every connection to Operelio is encrypted with TLS 1.2 or higher. Unencrypted requests are rejected outright. Once your data reaches our servers, it's encrypted at rest using AES-256-GCM with keys managed through AWS Key Management Service. Keys rotate on a schedule and are backed by hardware security modules.
When you connect a CRM, the OAuth tokens and API credentials are encrypted separately from your account data. They're never logged, never shown in the UI after initial setup, and revoked the moment you disconnect.
Uploaded files are stored in isolated S3 buckets with server-side encryption. File retention depends on your plan: 24 hours on Free, 30 days on Pro and Team, and 90 days on Agency. After the retention window, files are permanently deleted.
Billing is handled entirely by Stripe, a PCI Level 1 certified payment provider. Card details are entered directly into Stripe's secure forms, tokenised, and never transmitted through or stored on our servers. The only payment information we receive is the card type, last four digits, and expiry date.
Infrastructure
Built on AWS, locked down by default
Operelio runs on Amazon Web Services in the US-East (N. Virginia) region. All resources sit inside a dedicated Virtual Private Cloud. Databases and internal services have no public internet access. Traffic between components is encrypted, and network access is restricted through security groups and network ACLs.
A web application firewall protects against common attack vectors including SQL injection, cross-site scripting, and DDoS. AWS Shield provides always-on network-level protection. Rules are reviewed and updated as the threat landscape changes.
Authentication is handled by Clerk, which supports passwordless sign-in, OAuth providers (Google, GitHub), and multi-factor authentication. We implement role-based access control for all system access, following the principle of least privilege. API keys are hashed before storage, displayed once on creation, and rate-limited per key.
Databases are backed up daily with 30-day rolling retention. Backups are encrypted and stored in a separate AWS region. In the event of a failure, our recovery target is under four hours.
Privacy
We don't monetise your data
Your spreadsheets, CRM credentials, and processing history are yours. We will never sell, rent, or share your data with advertisers or third parties. We don't run tracking pixels or third-party analytics inside the app, and there are no external marketing tools watching what you do.
Your files will never be used to train machine learning models. We collect only the minimum data needed to run the service: your account details, the files you upload, and the processing configuration you choose. Nothing more.
Full details are in our privacy policy, which is written in plain language rather than legalese.
AI operator
The AI sees a summary, never your data
Operelio includes Bridgeant, an assistant you can ask to clean a file or get it ready for your CRM. To plan that work, Bridgeant sends an AI model a summary of your file: the column headers, how full each column is, the row and column counts, and the quality issues found in the data. Your actual cell values and your rows never go to the model.
This is built into the code, not left to a policy. The summary is assembled by one function that can only pass through headers and counts, and a second check rejects the request if any raw data is present. The model receives that summary, the list of actions it can take, and the message you typed. Nothing else about your file leaves your workspace.
You do not have to take our word for it. Under any Bridgeant reply, open “What did Bridgeant see?” to view the exact summary sent for that turn, down to each column header and count, alongside a plain statement of what was not sent.
Your files are never used to train models, and these summaries are not kept to improve one. Files themselves are deleted after your plan's retention window: 24 hours on Free, 30 days on Pro and Team, and 90 days on Agency. See the privacy policy for the full detail.
Compliance
Where we stand
GDPR and UK GDPR: fully compliant. We maintain lawful bases for processing, honor data subject rights, offer Data Processing Agreements with Standard Contractual Clauses, and follow the 72-hour breach notification requirement.
CCPA / CPRA: fully compliant. California residents can request access to or deletion of their personal data. We do not sell personal information.
ISO 27001: planned. Our information security management practices follow the standard and formal certification is on the roadmap.
Data residency: customer data is stored in AWS US-East by default. For organizations that require EU-based storage, get in touch and we can discuss options.
If your organization needs a Data Processing Agreement, we have a standard DPA ready to sign. We also complete security questionnaires and share penetration testing summaries on request. Email hello@operelio.com and we'll send it over.
Lawful basis
Who is responsible for what
When you upload a file to Operelio, two questions about lawful processing apply. The first is your question: do you have a lawful basis under GDPR, UK GDPR, CCPA, or your local regime to process the personal data in that file? The second is ours: what's our role in that processing? This section explains the split.
Your basis to upload. You upload the data, so the lawful basis question starts with you. In practice that's usually consent (the contact opted in), a contractual relationship (they're a customer or a prospect at a live opportunity), or legitimate interest (you have a documented reason to process them and that reason outweighs their privacy interest). The Operelio Terms of Service require you to warrant that you have a lawful basis for every file you upload. We don't ask you to prove it, but you sign that warranty when you sign in.
Our basis to process. We process your file as your data processor under a standard Data Processing Agreement. Our lawful basis is your contract with us: you've asked us to run a specific transformation, and we run it. For the Email Verifier & Finder specifically, that processing is a quality check: we confirm whether an inbox accepts mail, using EU-based verification providers. If you ask Operelio to recover missing or failed addresses, it rebuilds them only from the email patterns already in your own file, never from an outside contact database. We don't look up an address's owner, and we never sell or rent your list. Your file stays inside your account for your plan's retention window, then it's deleted. Separately, we keep a one-way hash of each verified address alongside its verdict for 7 days, so a recent verdict can be reused instead of re-checking the same address. That record can't be turned back into an address, and it carries nothing about you or your file.
What's shared, and what never is. Your files, recovered addresses, and any send outcomes you upload stay scoped to your own workspace. One thing is shared, and it's worth being precise about: when an address has already been verified anywhere on Operelio in the last 7 days, we reuse that verdict rather than re-checking the address. That record holds a one-way hash of the address, the verdict, and the score. No name, no company, no file, no account, and it's deleted after 7 days. Your list, your columns, and your uploaded send results are never shared, and your bounce history only ever tunes your own workspace's scoring.
Where Operelio doesn't help. Verification is not a consent check. If you upload a list you scraped from the web or bought from a source with no documented consent chain, we'll happily verify which addresses accept mail. We can't tell you whether you have permission to send to them. That's on you. Every paid plan includes a Do Not Contact list you can suppress against as an additional safeguard, but even that won't replace your own basis to process.
Full details on our role as your processor are in the privacy policy and the standard DPA, which we'll send on request. Email hello@operelio.com if your legal team needs to review.
Compliance
Do Not Contact list
For teams that need to honor suppression requests under CAN-SPAM, GDPR, CASL, or PECR, every paid plan includes a workspace-scoped Do Not Contact list. Upload your suppression file once, with emails, phone numbers, domains, or company names, and Operelio applies it automatically to your CRM pushes and workflow exports. You can also block whole countries when a region is off-limits, with one-click presets for the EU and for comprehensively sanctioned countries (Cuba, Iran, North Korea, Russia, Syria) to help keep outreach away from embargoed regions. The preset is a convenience, not a substitute for formal sanctions screening.
Health Check flags suppressed rows so you can review them, and the Email Verifier can optionally remove them from a verified list. Matching runs on your data inside your account, costs no credits, and never calls an outside service.
Free plans don't include the suppression list. Pro stores up to 5,000 entries, Team up to 25,000, and Agency up to 100,000, with cross-client-workspace global lists planned for a later release.
Incident response
If something goes wrong
Security incidents are detected through automated monitoring, WAF alerts, log analysis, and user reports. When something is flagged, we assess scope and severity, isolate the issue, and begin remediation. Affected customers are notified directly.
For confirmed breaches involving personal data, we follow GDPR Article 33: notification to the relevant authority within 72 hours, and direct communication to affected individuals describing what happened, what data was involved, and what we're doing about it. US breach notification follows state law requirements.
After every incident we run a post-mortem to find the root cause and close the gap. The findings are documented and the fix is verified before we consider the matter resolved.
Responsible disclosure
Found something? Tell us.
If you discover a vulnerability, email security@operelio.com with details of the issue. Please don't disclose it publicly until we've had time to investigate and patch.
We aim to acknowledge reports within 24 hours, assess severity within 48 hours, and begin remediation within five business days. Critical vulnerabilities are prioritized for immediate patching. We'll keep you updated weekly until the issue is resolved.
Questions about security?
We're happy to walk through our practices, share documentation, or complete your vendor security questionnaire.
This page describes our current security practices and is provided for informational purposes. No security measure is 100% effective. For specific security advice or legal guidance, consult a qualified professional.