# Security and Trust | OPPI > Explore OPPI's security architecture. Built with logically isolated infrastructure, AES-256 encryption, and strict privacy-first protocols. Canonical URL: https://oppi.au/security Site index for agents: https://oppi.au/llms.txt --- Security Security by architecture. We take a defensive-first approach to hospitality operations. Your venue's data is not just stored. It is isolated, encrypted, and protected at every layer. 1. 01 #### Isolated infrastructure OPPI operates on logically isolated cloud architecture with AES-256 encryption at rest and TLS 1.3 in transit. Point-in-time recovery enabled 2. 02 #### Identity governance Granular role-based access control ensures your venue data is only accessible by authorised personnel. Secure session persistence, MFA ready 3. 03 #### Privacy by design We treat venue data as a liability, not an asset. Your operational data is never sold or shared with third parties. Fully isolated operational environments 4. 04 #### Agentic safety Our AI agents operate within strictly defined sandboxes with no cross-organisation knowledge or data leakage. Context-aware security boundaries ### Logically isolated. Always encrypted. 01 ##### Encryption in transit and at rest Data is encrypted from the point it reaches our infrastructure using TLS 1.3, and stored with AES-256 encryption at rest. 02 ##### Continuous infrastructure monitoring Our cloud provider monitors infrastructure health, access patterns, and anomalous activity. We review alerts and audit logs regularly. 03 ##### Logical data isolation Venue data is logically isolated at the database level. Each customer's data is partitioned so one organisation cannot access another's information. 04 ##### Data residency Venue data is hosted on enterprise cloud infrastructure in Singapore (AWS ap-southeast-1), encrypted at rest, with point-in-time recovery enabled. 05 ##### AI processing, disclosed AI tasks are routed to OpenAI, Anthropic (Claude), Google (Gemini) and Perplexity under data processing agreements with each provider. Your data is sent only to answer the task at hand, is never used to train provider models, and trains only your venue's own model. 06 ##### Deletion, with a timeframe Request deletion and your data is removed in full, backups included, within 30 days. Your operational history belongs to your venue, not to us. End-to-end AES-256 + TLS 1.3 ##### Data residency Our primary database infrastructure is hosted in Singapore (AWS ap-southeast-1). Application hosting and AI processing may utilise servers in additional regions. For full details on where your data lives and cross-border disclosures under Australian Privacy Principle 8, see Section 07 of our [Privacy Policy](https://oppi.au/privacy). ### Compliance roadmap We are building OPPI to meet industry standards from day one. As we scale, we are actively working toward the following certifications. ISO 27001 Planned SOC 2 Type II Planned GDPR Compliant APP Compliant Servance Pty Ltd ยท oppi.au SEC-2026-001 ### Need more detail? If your venue has specific security requirements or compliance needs, we are happy to discuss them directly. [Contact the security team](mailto:security@oppi.au)