Security at OpenTag
OpenTag works only in the channels you invite it into, uses the access of the person asking, and waits for a person before it sends, spends, submits or purchases anything.
The same rules apply to every model a task goes to.
Access and approvals
OpenTagAPP9:40
Sofi Alejandra9:41
OpenTagAPP9:41
Your data
Kept separate
Each workspace runs in its own isolated environment. Memory, files and learned formats never cross between customers.
Never used for training
Your messages, files and connected data are never used to train models, by OpenTag or by any provider it routes to. This is in our contracts.
Yours to delete
Delete any stored context, or all of it, at any time. Deletion requests complete within 30 days.
Encrypted
TLS 1.3 in transit and AES-256 at rest. Integration credentials sit in a separate vault with per-tenant keys.
When a model gets it wrong
Any model can make a mistake. OpenTag cites its sources, names the model it used and shows its plan, so you can check the work or stop it.
If a tool returns an error, OpenTag stops and tells you. It doesn't retry sensitive actions on its own.
Jordan Lee2:14
OpenTagAPP2:14
The GitHub tool returned a permissions error, so I stopped. Nothing was changed.
Used GPT-5.5 · 1 source
- In progress
SOC 2 Type II
The report goes in the Trust center when the audit is done
- Live
Trust center
trust.tryopentag.com - Available
Data processing addendum
Read the DPA - On request
Penetration test summary
team@tryopentag.com - Enterprise plan
SSO, SCIM, audit log export and security questionnaires
See pricing