OPM Technologies

Security

Security is part of every OPM product.

Payroll records, customer pipelines and project files are all sensitive by default. Here is what each OPM product actually does about it, in plain language rather than a badge.

How it fits together

The path your data takes.

From the moment someone in your organisation signs in to the backup that sits behind the record.

  1. 01Your organisationYour people sign in with their own accounts. Sessions expire.
  2. 02Encrypted connectionEvery request travels over HTTPS.
  3. 03OPM productWorkforce, Finpilot, Billing, CRM, Airform or Projects.
  4. 04Role-based accessEach person sees only what their role permits, checked on every request.
  5. 05Encrypted dataData at rest is encrypted on the database layer.
  6. 06Backups & historyScheduled backups, and an audit trail where the product keeps one.

Your data remains your data.

OPM holds your records so your teams can work on them. It does not own them, sell them or share them.

  • You decide who in your organisation sees what, by role.
  • Your data is used for the purpose the product exists to serve, and nothing else.
  • It is not shared with or sold to third parties.

Leaving is part of it too: how to request deletion.

By product

What each product holds.

Each product, its own kind of data, one set of platform practices underneath them.

Workforce

Employee & payroll data

Personal details, salary structures, payslips and statutory records. Access is scoped by role, so a manager sees their team and not the payroll register.

Finpilot

Accounting & tax data

Ledgers, invoices, expenses, GST records and financial reports. Access is scoped by role, like every OPM product, so the people who see the books are the people you chose.

OPM CRM

Customer & sales data

Contacts, accounts, opportunities and the activity history attached to them. Record ownership and team hierarchy decide who can read and edit what.

OPM Projects

Business & project data

Project plans, tasks, files and timesheets. Project membership controls visibility, so client work stays inside the team delivering it.

OPM Billing

Invoice & payment data

Customers, quotes, invoices, subscriptions and payment records. Granular permissions, approvals and an immutable audit log decide who can issue, edit or void a document.

Airform

Respondent & consent data

Form responses, respondent contact details and the consent recorded with each one. Consent is logged per response and can be withdrawn, and retention is set per workspace.

Platform practices

What's in place across every product.

Encryption in transit and at rest

All traffic to OPM products is served over HTTPS. Data at rest is encrypted on the database layer.

Role-based access

Every user sees only what their role permits, enforced on every request, not just in the interface.

Regular backups

Production data is backed up on a regular schedule, so a failure does not mean lost payroll, pipeline or project history.

Credential hygiene

Passwords are hashed, not stored in plain text, and sessions expire. OTP-based verification is used at sign-up.

Data handling & compliance.

Every OPM product is built with India’s Digital Personal Data Protection Act, 2023 in mind: data is collected for the stated purpose the product exists to serve, access is restricted by role, and it is not shared with or sold to third parties.

This is a statement of how the product is built, not a certification. OPM does not hold a third-party security certification today, and this page will name one specifically the day that changes rather than imply one it doesn’t have.

Certifications

Held today.

None held or in progress today. We’d rather this section be empty than carry a logo we haven’t earned.

Have a specific security question?

Talk to us directly. We'd rather answer it than leave it to a badge.