Opine

Security at Opine

Last Revised: September 26, 2026

Athletes, creators, and organizations trust Opine AI, Inc. (“Opine,” “we,” or “us”) with their voices, their stories, and their social accounts. This page describes how we protect that data: how we govern security, how we encrypt and store data, how our infrastructure is secured, and the practices our team follows every day.

Governance

Opine’s leadership establishes our security policies and controls, monitors compliance with those controls, and proves our security and compliance to third-party auditors. Our policies are approved by management, acknowledged by every team member, and reviewed every year.

Our policies are based on these principles

  1. 01.Access is limited to people with a legitimate business need and granted on the principle of least privilege.
  2. 02.Security controls are implemented and layered according to the principle of defense-in-depth.
  3. 03.Security controls are applied consistently across every area of the company.
  4. 04.Controls are implemented iteratively, continuously improving their effectiveness, auditability, and ease of use.

Security and compliance at Opine

Opine is in the observation period for its SOC 2 Type II audit. Our controls are monitored continuously through Vanta.

Opine maintains compliance with

  • GDPR
  • CCPA

Data protection

Data at rest

Customer data is encrypted at rest with AES-256 in our application database and in the file storage that holds uploaded audio, images, and video. Company laptops use full-disk encryption.

Data in transit

All traffic to Opine is served over HTTPS using TLS 1.2 or higher, and HTTP Strict Transport Security (HSTS) keeps browsers from connecting over plain HTTP. Connections between our services and our vendors are encrypted as well.

Secret management

Tokens for the social accounts you connect are encrypted and held in a dedicated secrets vault, isolated per user, organization, and platform; our database stores only a reference to them. Application secrets live in our hosting providers’ encrypted environment stores, never in source code, and links to stored media are signed and expire automatically.

Infrastructure security

Cloud hosting

Opine runs entirely on established cloud providers: Vercel for the web application, Convex for our database and backend, and Microsoft Azure for file storage. We operate no servers or data centers of our own, and each provider maintains its own independently audited security program.

Logging and monitoring

Sign-ins, administrative actions, and changes to security settings are logged with who acted, when, and on what. Logs are protected from tampering, and alerts notify our team of significant events.

Vulnerability management

Every code change is scanned by static analysis before it merges, and the full codebase is rescanned weekly. Dependencies are monitored for known vulnerabilities, and public-facing production systems are scanned at least quarterly. The Opine application and infrastructure also undergo penetration testing, which we repeat regularly. Findings are fixed on deadlines set by severity.

Backups and continuity

Production data is backed up separately from the systems it protects. We test restoring from backup, along with our disaster recovery plan, at least once a year.

Internal security practices

Access control

Access to production systems and customer data is role-based, granted on least privilege, and denied by default. Every person has their own account, and multi-factor authentication is required for privileged access wherever a system supports it. We review access quarterly and remove it within one business day of someone leaving.

Secure development

All code is version-controlled. Changes are peer-reviewed and must pass automated tests and security checks before they can reach production, so no one can ship a change on their own. Production customer data is not used in development or testing.

People

Team members with access to production pass a background check, sign confidentiality agreements, and complete security awareness training when they join and every year after. Everyone acknowledges our security policies at hire, and company devices lock automatically when left unattended.

Vendor management

Before a vendor handles confidential data, we assess its security and put a written agreement in place. We review our vendors’ security at least annually.

Incident response

Our documented incident response plan covers how incidents are reported, triaged by severity, investigated, contained, and resolved, followed by a review of what we can improve. If an incident affects your data, we will notify you without undue delay, as required by our agreements and applicable law.

Data privacy

We collect only the data we need to provide Opine, and we delete customer data within 90 days of the end of a customer’s contract. You can ask us to access or delete your personal data at any time. Our Privacy Policy explains what we collect, how we use it, and the rights you have under GDPR, CCPA, and other privacy laws.


Reporting a vulnerability

Opine welcomes reports from security researchers. If you believe you have found a vulnerability in our services, we want to hear about it, and we will work with you to understand and resolve it quickly.

How to Report

Email security@opine.co. This address is monitored by our security team and is the only channel we ask you to use for vulnerability reports. Please do not open a public issue, post the details publicly, or contact individual employees.

So that we can reproduce the issue quickly, please include:

  • A description of the vulnerability and the impact you believe it has;
  • The steps required to reproduce it, including any URLs, requests, accounts, or payloads involved;
  • Any supporting material, such as screenshots, a proof-of-concept, or logs; and
  • How you would like to be credited, if at all.

A machine-readable version of this contact information is published at /.well-known/security.txt in accordance with RFC 9116.

What to Expect

  • We will acknowledge your report within three business days of receiving it.
  • We will confirm whether we have reproduced the issue, and give you an assessment of its severity, within ten business days.
  • We will keep you informed as we work on a fix, and let you know when it has shipped.
  • We ask that you give us 90 days from your initial report before disclosing the issue publicly, and we will work with you if you need a different timeline.

Opine does not currently operate a paid bug bounty. We do not offer monetary rewards for reports, but we are glad to credit researchers publicly for valid findings where they would like us to.

Scope

The following are in scope:

  • opine.co and www.opine.co, including the Opine web application;
  • Our public APIs and webhook endpoints.

The following are out of scope:

  • Services operated by our vendors and subprocessors. Please report those to the vendor directly; tell us as well if the issue affects Opine data.
  • Findings from automated scanners that come with no demonstrated impact, and reports that amount only to a missing hardening header, a TLS configuration preference, or a version-disclosure banner.
  • Social engineering of our staff, customers, or vendors; physical attacks; and any form of denial-of-service or volumetric testing.
  • Vulnerabilities requiring a compromised device, a rooted or jailbroken device, or a privileged position already held on a victim’s machine.

Testing Guidelines

When investigating an issue, please use only accounts you own or have explicit permission to test with. Do not access, modify, or retain data belonging to anyone else. If you encounter personal data, stop, do not save a copy, and tell us what you found in your report. Do not degrade our service for other users, and do not run automated tooling at volumes that would.

Safe Harbor

If you make a good-faith effort to comply with this policy during your research, we will consider your testing authorized, we will not pursue or support legal action against you in connection with it, and we will help make clear that your actions were authorized if a third party brings such action. If you are unsure whether a particular test is within this policy, ask us at security@opine.co before you begin.