opheli.ai
Product Workflow Blueprints Security Pricing Help
Sign in Request Beta Access
Product Workflow Blueprints Security Pricing Help Sign in Request Beta Access

Trust & policies

Security

How opheli.ai handles Provider keys, account security, Trust Engine controls, and practical user responsibilities without claiming certifications.

Final legal review required before public launch. This page is professional draft policy content and must be reviewed by qualified counsel before public launch.

Table of contents

Jump to the right section

Provider keys Account security Trust Engine Limitations

Trust & policies

Legal and trust

Terms Privacy AI Disclaimer Acceptable Use Data Processing Security Provider Usage Billing Terms Support Policy Cookie Policy Imprint

Provider Vault

Provider keys are encrypted at rest and handled server-side

Live Provider keys are stored encrypted at rest, used server-side for user-requested Provider calls, and not shown again after save.

Users should rotate or revoke Provider keys directly in the Provider dashboard if they suspect compromise or no longer want opheli.ai to use that Provider account.

Account

2FA and recovery controls help protect access

Where enabled, opheli.ai supports 2FA setup, challenge flows, recovery codes, trusted-device posture, and account security settings.

Users remain responsible for protecting passwords, email accounts, 2FA devices, recovery codes, and Provider dashboards.

Trust Engine

The Trust & Integrity Engine is app-level protection

The Trust & Integrity Engine can record security events, audit high-impact actions, surface system health, throttle sensitive actions, and support Shield Mode or maintenance controls where configured.

These controls are application-level protections for a VPS deployment. They do not replace Nginx rate limits, firewalling, backups, DDoS protection, WAF/edge controls, Provider-side abuse controls, or qualified security review.

No certification claim

No system is perfectly secure

Do not upload secrets unnecessarily. Do not store Provider secrets in Context. Monitor Provider dashboards directly for unexpected usage.

opheli.ai does not claim SOC 2, ISO, HIPAA, GDPR, AI Act, or other certification/compliance status unless separately documented and legally verified.

opheli.ai

Structured AI execution with Context, Operators, Runs, Artifacts, and Mission Replay.

Help Center Contact Support Mission Control
landing.footer.terms landing.footer.privacy AI Disclaimer Acceptable Use Security Provider Usage Cookie Policy landing.footer.imprint hello@opheli.ai

© 2026 opheli.ai. All rights reserved.

Trust & policies

Cookie choices for opheli.ai

Necessary cookies keep login, session security, and core app surfaces working. Optional categories stay off until you say yes.

Read Cookie Policy Read Privacy

Trust & policies

Customize cookie settings

Choose which optional categories opheli.ai may store or use on this device. Necessary cookies remain enabled.

Necessary

Always on for login, security, CSRF, session, and core execution surfaces.

On