Privacy
Every record in OperatorKit is scoped to a single organization. Tenant isolation is enforced in the data-access layer itself — cross-organization reads and writes are rejected before they reach the database.
Credentials and channel secrets are encrypted at rest with AES-256-GCM, and every decryption is itself written to the audit trail.
The audit trail is append-only. There is no interface, for us or for you, that edits or deletes history.
We collect only what the platform needs to operate on your behalf: the records you bring, the communications you authorize, and the operational telemetry required to keep the system healthy. We do not sell or share organizational data.
Questions or data requests: contact your OperatorKit administrator or reply to any message from the platform.