Third Party Index

Snapshot 50306

Document
Trust center
URL
https://trust.opslevel.com/
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
browser
Size
82065 bytes
SHA-256 (raw)
3deadf2c3058128f6e4600fbbcd703eea421e7757bbee18ac01ccf819e1e68b1
SHA-256 (normalized text)
f6ec1ce8a200d1c00542b303f2f0ee4df521c3673c683305f6bd7c16b4d94db6

Normalized text

Scripts and page chrome removed; this is what change detection compares.

OpsLevel is continuously monitoring its overall security posture.
Announcements
SOC2 Type II
Published on Jul 16, 2025
We have received our 2024-2025 SOC2 Type II report and it is now available to request below.
Compliance
Documentation of our compliance against global standards including certifications, attestations, and audit reports.
Security
Policies
Continuous monitoring
Note: If a control is passing all tests, it will be marked as green. If a control has a failed test that was not resolved within the past 7 days, it will be marked yellow.
App Security
Web Application Firewall
Data Security
Daily Database Backups
Encryption at Rest
System Access Control Policy
Infrastructure Security
Cloud Data Storage Restricted
Logs Centrally Stored
Multiple Availability Zones
Password Policy
Security Patches Automatically Applied
Network Security
Denial of Public SSH
Firewalls
Organization Security
Acceptable Use Policy
Code of Conduct
Disaster Recovery Plan
Incident Response Plan
Incident Response Team
Security Training
Product Security
Databases Monitored & Alarmed
Hard-Disk Encryption
MFA on Accounts
Servers Monitored & Alarmed
Subprocessors
Amazon Web Services
Cloud Infrastructure and Security
Data location: USA, Northern Virginia
Datadog
Monitoring and Logs
Data location: USA
Sentry
Error Tracking
Data location: USA
Sendgrid
Transactional Email
Data location: USA
Beamer
In App Update Messages
Data location: USA
Mixpanel
User Analytics
Data location: USA
FAQ (Frequently Asked Questions)
4
We are SOC2 Type II compliant and are looking into making any changes needed to be GDPR compliant. If there is a compliance framework we currently do not meet the standards of please reachout to your customer success representative and we will investigate the requirements for it.
OpsLevel uses a mixture of OpenAI and Anthropic models to power select features.
Business terms for OpenAI can be found here: https://openai.com/policies/business-terms/
Business terms for Anthropic can be found here: https://www.anthropic.com/legal/commercial-terms
The data shared with AI subprocessors for processing is dependent on the AI feature being used. Examples include:
Generated Component Descriptions: Repository directory listings, and the contents of files within that repository (specific files determined when generating the description).
Generated Document Summaries: content of the markdown file being summarized.
AI Powered Catalog Engine: Aliases from events passed to OpsLevel (e.g. repository names, service aliases from integration webhooks)
Maintenance Agent: Generate code suggestions for user-driven initiatives across many repositories. Customer code is never stored in OpLevel or retained by subprocessors.
Please contact your OpsLevel Customer Success team for more information
OpsLevel commercial contracts with our AI subprocessors (OpenAI & Anthropic) apply zero-day data retention. Furthermore, our data is not used for training or model development.
Additional details
OpsLevel is a microservice catalog & dev portal that lets software eng teams ship faster without sacrificing security, quality, or reliability.
Privacy details
OpsLevel Privacy Policy
Privacy URL