Workspace isolation
Every customer record is workspace-bound. Database row-level policies and server authorization are tested against owner, member, outside-user, and service-only access paths.
Security and data handling
Oplisk is built to keep customer workspaces separate, private files private, automated traffic honest, and access reversible. This page describes the controls operating today—not a future certification.
Current controls
Every customer record is workspace-bound. Database row-level policies and server authorization are tested against owner, member, outside-user, and service-only access paths.
Room files live in private object storage. A file does not become publishable or downloadable until the production malware scanner returns a clean result; scanner failure keeps the file blocked.
Data-room guests use time-limited verification and revocable access. Workspace owners can remove a guest when the relationship changes while preserving the prior room history.
Stripe, email, and scanner callbacks cross signed or secret-bound server endpoints. Duplicate and out-of-order events are reconciled before customer state changes.
Known mail-security scanners stay separate from human link activity. Raw network addresses are discarded after request processing rather than retained as investor profiles.
Workspace owners can export customer data and begin deletion. The lifecycle removes private objects and customer rows after the retention window, with an operational record of completion.
Hosting and providers
Oplisk’s dedicated Supabase project, primary Vercel application functions, and Google Cloud malware scanner are configured in Frankfurt. Stripe and Postmark process the billing and email functions described in the privacy notice.
Oplisk does not currently claim SOC 2 or ISO 27001 certification. Provider regions are not a promise that every network or support operation remains in one country; contractual processing and transfer details are stated in the privacy notice.
Questions or disclosures
Send security questions or a responsible disclosure to contact@anyjoi.com. Include the affected URL, reproducible steps, and the impact you observed; do not access another customer’s data or disrupt the service.