☰ On this page
Where your data lives
Oprex runs on infrastructure operated by PT Kinetikum Indo Solusi in Indonesia. Application data — specifications, requirements, tests, releases, bugs, tickets, notes, memory — lives in a per-tenant partition of a managed PostgreSQL database; uploaded assets and OTP evidence live in object storage (MinIO) under a per-tenant prefix.
Everything in the lifecycle is reachable through the API, and every project can be exported as JSON from Settings → Your data, so an export is always possible without asking us.
Who can read it
🏢 Tenant isolation
Every record carries a tenant. Cross-tenant reads are not a permission you can be granted — they are refused with a 403, including for Kinexa staff on the ordinary panel routes.
🔐 Per-project access
Membership decides which projects you see. The rule is defined once and applied to lists, counts, and detail pages alike, so a count can never leak what a list hides.
🕶️ Confidential groups
A confidential group never appears on a public surface and forces its repositories private, regardless of what anyone sets afterwards.
Credentials and keys
- API keys are stored as SHA-256 hashes. We cannot show you a key again after creation because we do not have it.
- Keys carry scopes — read, write, admin; write methods are refused at the authentication layer for read-only keys, not by per-route convention.
- Keys can be bound to a single group or project, disabled, or deleted — and every key records when it was last used.
- Authentication is single sign-on; Oprex never sees or stores your password.
AI and your data
This is the question developers ask first, so the answer is blunt:
- Your content is not used to train models. Not ours, not a provider's.
- You choose the provider. Bring your own OpenAI-compatible or Gemini-compatible endpoint and key, or use the shared default through the Kinexa Gateway with a daily allowance per workspace and per member.
- Memory is explicit. Nothing is silently added to an AI context. Memory documents are included only where you attach them, which is why the boundary is auditable rather than assumed.
- Agents inherit your permissions. Connecting an MCP client never widens what is visible; the key acts as the person who created it.
- The test recorder masks in the browser. Passwords, card numbers, and national IDs typed during an OTP recording are masked before anything leaves your computer.
Availability and continuity
Live service status is published at status.oprex.id, including the OTP runner and object storage. Databases are backed up on a schedule to a separate storage target and restores are exercised rather than assumed.
Oprex is in beta. We would rather you know that from this page than discover it from an incident. Where a guarantee does not exist yet, it is not written here.
Leaving, grace, and deletion
If a paid plan lapses, nothing is deleted: the workspace enters a 30-day grace period with reminders, and you can export at any time. You can also request deletion of all workspace data; it is scheduled 14 days out, cancellable until then, and confirmed by email when done — as Indonesia's PDP law requires.
Certifications — where we actually are
We hold no third-party security certification today, and we will not imply otherwise. What exists is a documented architecture, enforced tenant and project isolation, hashed credentials, scoped keys, and an audit trail — all of which you can verify against the product rather than a brochure.
If your procurement process requires a formal attestation — SOC 2, ISO 27001, or an Indonesian PDP compliance statement — talk to us about timelines before you commit. We would rather tell you the honest date than the convenient one.
Reporting a vulnerability
Report it through the support portal marked as a security issue. Please do not post it publicly first. We confirm receipt, keep you updated, and credit you if you want to be credited.