01Introduction
Security, privacy and compliance are fundamental to how Opei Business Suite is designed, developed and operated.
This Compliance & Security Overview explains the measures implemented by Opei Technologies LLC (“Opei”, “we”, “our”, or “us”) to help protect customer information, maintain platform reliability and support compliance with applicable legal and regulatory requirements.
This document is provided for informational purposes only and does not modify or replace any agreement between Opei and its customers.
02About Opei
Opei Technologies LLC develops and operates Opei Business Suite, a cloud-based business management platform.
Opei provides software and technology services, including:
- Business management software
- Payment technology
- Point of Sale (POS)
- Inventory management
- Customer management
- Business analytics
- APIs and developer tools
- Workflow automation
- Virtual card technology
- Business integrations
Unless expressly stated otherwise, Opei Technologies LLC is not a bank, payment institution, money transmitter, electronic money issuer or other regulated financial institution.
Where regulated financial services are available through the Platform, they are provided by independent licensed financial institutions or regulated partners operating under their own licences, regulatory obligations and legal agreements.
03Security Principles
Our security programme is built around several core principles:
- Security by Design
- Least Privilege Access
- Defence in Depth
- Continuous Monitoring
- Secure Software Development
- Responsible Disclosure
- Continuous Improvement
Security is considered throughout the software development lifecycle.
04Infrastructure Security
Opei uses commercially reasonable security controls designed to protect the Platform and customer information. Infrastructure protections may include:
- Secure cloud infrastructure
- Encrypted communications (TLS)
- Firewalls and network segmentation
- Access logging
- Monitoring and alerting
- Secure infrastructure provisioning
- Backup and recovery procedures
- High availability architecture where appropriate
Infrastructure providers may differ depending on deployment requirements.
05Application Security
Security measures incorporated into the Platform may include:
- Secure authentication
- Password hashing
- Session management
- Multi-factor authentication for privileged access where supported
- Role-based access control
- Secure API authentication
- Input validation
- Protection against common web vulnerabilities
- Security logging
- Dependency management
- Regular software updates
Development practices evolve as security standards change.
06Encryption
Opei uses encryption technologies designed to protect information.
Data in Transit — Communications between users and the Platform are encrypted using industry-standard Transport Layer Security (TLS).
Data at Rest — Sensitive information may be encrypted while stored using commercially recognised encryption technologies where appropriate.
Encryption standards may evolve over time as technology advances.
07Identity & Access Management
Access to production systems is restricted to authorised personnel with a legitimate business need. Access controls are based on the principles of:
- least privilege;
- role-based permissions;
- authentication;
- authorisation;
- periodic access review.
Administrative actions may be logged for security and operational purposes.
08Customer Data Protection
Customer Data remains under the control of the customer. Opei processes Customer Data only:
- to provide the Services;
- to maintain Platform security;
- to fulfil contractual obligations;
- to comply with applicable law.
We do not sell Customer Data.
09Privacy
Opei is committed to protecting personal information. Our privacy practices are described in our Privacy Policy.
Where required by applicable law, customers may request access to, correction of or deletion of personal information, subject to legal limitations.
10Security Monitoring
Opei continuously monitors Platform health and security using operational monitoring tools. Monitoring may include:
- system health;
- authentication events;
- API activity;
- infrastructure monitoring;
- application logs;
- suspicious activity detection;
- security alerts.
Monitoring supports the identification and investigation of security events.
11Incident Response
Opei maintains procedures for responding to security incidents. These procedures are designed to:
- identify incidents;
- contain threats;
- investigate root causes;
- restore affected services;
- communicate with affected customers where required;
- implement corrective actions.
Where required by law or contractual obligations, affected customers will be notified without unreasonable delay following confirmation of a reportable security incident.
12Business Continuity & Disaster Recovery
Opei maintains business continuity and disaster recovery procedures intended to support Platform resilience. These procedures may include:
- infrastructure redundancy where appropriate;
- backup procedures;
- recovery planning;
- operational testing;
- documented response processes.
Recovery procedures are reviewed periodically and updated as necessary.
13Software Development
Opei follows a structured software development lifecycle that incorporates security considerations throughout design, development, testing and deployment. Development practices may include:
- peer code review;
- automated testing;
- dependency management;
- vulnerability remediation;
- staged deployments;
- change management.
14Third-Party Providers
To operate the Platform, Opei works with selected third-party service providers. These may include providers of:
- cloud infrastructure;
- communications;
- analytics;
- monitoring;
- customer support;
- identity verification;
- payment processing for Platform subscription fees.
Third-party providers are evaluated using commercially reasonable selection criteria appropriate to the services provided.
15Financial Services
Certain Platform features enable customers to access regulated financial services through licensed third-party providers. These may include:
- payment processing;
- card issuing;
- banking services;
- foreign exchange;
- remittance;
- settlement services.
These regulated services are not provided by Opei Technologies LLC unless expressly stated otherwise.
Each provider remains responsible for its own licences, regulatory compliance, customer onboarding, compliance obligations and service availability.
16Compliance
Opei designs its Platform with recognised security and privacy principles in mind.
Depending on business needs, customer requirements and future operational maturity, Opei may pursue independent audits, certifications or compliance programmes.
Any certifications or attestations will be published only after they have been formally obtained.
17Customer Responsibilities
Customers also play an important role in maintaining security. Customers should:
- protect account credentials;
- enable multi-factor authentication where available;
- keep devices and browsers updated;
- manage user permissions appropriately;
- report suspected security incidents promptly;
- comply with applicable laws relating to their own business activities.
18Responsible Disclosure
If you believe you have identified a security vulnerability affecting Opei Business Suite, we encourage responsible disclosure.
Please report security issues privately to security@opei.business.
Please include sufficient information to allow our team to investigate. Do not publicly disclose vulnerabilities until Opei has had a reasonable opportunity to investigate and address the issue.
19Changes to this Overview
This Compliance & Security Overview may be updated periodically to reflect changes in our services, technology, legal requirements or security practices.
The latest version will always be available on our website.
20Contact
Opei Technologies LLC — Security Team
Email: security@opei.business
Privacy: privacy@opei.business
General Enquiries: info@opei.business
Website: https://opei.business
This document is provided for informational purposes only. It does not create contractual obligations, warranties or guarantees and should not be interpreted as a certification, legal opinion or commitment to any specific compliance framework unless expressly stated by Opei Technologies LLC.
