Compliance 15 min read

Platform Security: 2FA, SSO, Audit & Encryption — OpsIQ

Platform Security: 2FA, SSO, Audit & Encryption — OpsIQ

In today's digital landscape, ensuring robust platform security is paramount for enterprises. OpsIQ offers a comprehensive security framework that integrates two-factor authentication (2FA), OpenID Connect (OIDC) single sign-on (SSO), System for Cross-domain Identity Management (SCIM), immutable audit logs, AES-256 encryption, and per-tenant isolation.

Key Security Features

  1. Authentication & Access Control
  • Two-Factor Authentication (2FA): Each admin can enable Time-based One-Time Password (TOTP) 2FA using apps like Google Authenticator or Authy. This adds an extra layer of security by requiring a second form of verification.
  • OIDC SSO & SCIM: For Business and Enterprise plans, OpsIQ supports OIDC SSO and SCIM auto-provisioning, allowing seamless integration with your identity provider (IdP). This ensures that user onboarding and offboarding are streamlined and logged.
  • Brute-force Protection: Automatic lockout mechanisms are triggered after multiple failed login attempts, enhancing security against unauthorized access.
  1. Authorization
  • Role-Based Access Control: OpsIQ employs a granular role-based access system, ensuring that users only have access to the resources necessary for their roles. This minimizes the risk of unauthorized access to sensitive data.
  1. Audit & Compliance
  • Immutable Audit Logs: Every action taken within the platform—whether by a human or AI—is recorded in an append-only log. This includes details such as the actor, IP address, time, and result of the action, ensuring full accountability.
  • Security Events Monitoring: OpsIQ provides real-time monitoring of security events, allowing for quick identification and response to potential threats.
  1. Data Protection
  • Encryption: All data is protected using AES-256 encryption at rest and TLS 1.3 for data in transit. This ensures that sensitive information remains secure during storage and transmission.
  • Per-Tenant Isolation: Each cloud workspace operates within its own tenant boundary, with separate encryption keys, preventing cross-tenant data access.
  1. AI Safety
  • Registered Action Contracts: OpsIQ's AI can only perform actions that have been explicitly registered and approved, preventing unauthorized operations. Risky actions require human confirmation, adding an additional layer of oversight.

Incident Response & System Protection

OpsIQ is equipped with a robust incident response framework, ensuring that any security incidents are managed effectively. The platform includes features such as:

  • Manual Lockout Release: Administrators can quickly release locked accounts without waiting for timers, ensuring minimal disruption.
  • Health Diagnostics: Continuous monitoring of the platform's health provides insights into its operational integrity, allowing for proactive management of potential issues.

Compliance & Trust

OpsIQ is committed to maintaining a transparent compliance posture. While the platform currently aligns with GDPR, UK GDPR, and CCPA regulations, formal certifications such as SOC 2 Type II and ISO 27001 are on the roadmap. The company emphasizes honesty about its current capabilities and future goals, ensuring that clients are well-informed.

Conclusion

OpsIQ's security framework is designed with a focus on authentication, authorization, auditing, and data protection. By integrating advanced security measures and maintaining a commitment to compliance, OpsIQ provides enterprises with the tools necessary to safeguard their digital assets effectively.