Built with your data
in mind
SmartOps Copilot connects to sensitive systems like your inbox and CRM, so protecting that access is core to how we build.
Connected account credentials and OAuth tokens are encrypted at rest with AES-256-GCM before they're stored. They're only decrypted in memory when needed to make an authorized request on your behalf.
All traffic to and from SmartOps Copilot is encrypted over HTTPS/TLS, including requests to connected providers like Google and Microsoft.
Sign in with Google, Microsoft, or a one-time email code — SmartOps Copilot never asks for or stores your account passwords.
We request only the permissions each integration needs to do its job, and you can review or revoke connected account access at any time from your dashboard.
SmartOps Copilot runs on established cloud infrastructure with isolated environments for application and database layers.
This page covers the fundamentals of how we handle security today. We’re actively documenting our full data-handling and compliance posture as the platform matures — reach out if you need details for a review.
Have a security question?
For security disclosures, data requests, or vendor security reviews, reach out directly.