How Operlio protects your workspace

A summary of the protections built into Operlio. For data practices, see the Privacy Policy.

Auth sessions

Signed session tokens after password authentication. Passwords are hashed with bcrypt. Sessions live in HttpOnly cookies and expire on a fixed lifetime.

Tenant isolation

Each company has its own workspace. API and sync paths scope jobs, customers, photos, invoices, and team data to the signed-in user's company. That check runs on the server, not only in the UI.

Audit log

Sensitive actions are recorded with actor and timestamp: registration, login, invites, payments, workspace writes, permission denials, and account deletion.

Encrypted transport

Production traffic is served over HTTPS/TLS so credentials, job details, and photos are encrypted in transit between browsers and Operlio.

Photo storage

Job proof photos are stored as files on the company workspace, with access gated by an authenticated company context.

Operational controls

Role-based permissions (owner, manager, crew), invite-based onboarding, and before/after photo requirements.

AI assistant connections

Connecting an MCP-compatible AI assistant is opt-in, scoped to a key you generate for your own company only, and read-only until you turn on specific permissions one at a time (schedule, customers, quotes, invoices, customer messages, service catalog). It can never change billing or team roles, or permanently delete anything, and every change it makes is recorded in the audit log, the same as a person's edit.

See it yourself

Create a workspace and these protections are already running underneath it from the first job you add.