• Models
  • Rankings
  • Apps
  • Chat
  • Enterprise
  • Pricing
  • Docs
LoginSign up

Platform Data Security Overview

Last updated on: 2026-10-05

This document describes the technical and organisational measures Opper applies to customer data on the platform. It is the security overview referenced in section 3.1 of the Data Processing Agreement and the policy named in security.txt.

Opper's information security management system is certified against ISO/IEC 27001:2022. The controls it covers and the policies behind them are published on the Opper trust center together with the sub-processor register, the certificate is available there on request, and the trust center is continuously monitored.

Contents

  1. 1. Platform and hosting
  2. 2. What Opper stores
  3. 3. Files
  4. 4. Encryption and isolation
  5. 5. Backups
  6. 6. Deletion
  7. 7. Incidents and vulnerability reports
  8. 8. Sub-processors
  9. 9. Certification and documents

1. Platform and hosting

The shared platform, the web application and the API service, runs in the Amazon Web Services Stockholm, Sweden region. Traces, routing tables, scoring history and usage metadata are stored there. Dedicated and customer-hosted deployments, available on Enterprise plans, run where the customer agreement specifies.

Model inference runs on the route selected for each request. Every route publishes where inference runs and what the provider retains, on the model and provider pages, and the routes that run in Europe are listed on EU-hosted models. Inference is not restricted to the European Economic Area by default; model access rules on the Control Plane can restrict which routes a project may use.

Access to the platform requires an authenticated user or a valid API key. Sign-up, login and password flows are handled by Auth0. Enterprise plans add single sign-on with SAML and audit logging of user actions.

2. What Opper stores

For every call, Opper records usage metadata: the model, token counts, latency, status and cost. These records power billing and analytics and are kept for five years.

Prompts and responses are not stored unless a retention rule enables tracing. With tracing on, spans with their inputs and outputs are kept for the effective retention period, which an organisation sets between 1 and 30 days and a project can shorten to 0. The shortest enabled rule that applies wins. Under a zero-day rule, new calls store no trace content; traces created earlier keep the expiry they were given.

Model providers may retain request and response content for abuse monitoring, depending on the route. Routes with zero data retention, where the provider keeps nothing after the response is served, are marked as such in the model directory, and each provider page shows retention and training posture per route.

Opper does not use customer data to train models. Each provider's training posture is recorded per route.

3. Files

Files uploaded through the API are stored in a private S3 bucket, segregated per organisation and encrypted with Amazon S3 managed keys. They persist until the customer deletes them or until an expiry the customer sets. In a scope with a zero-day retention rule, uploads are rejected and existing files are scheduled for permanent deletion.

4. Encryption and isolation

Application data is stored in Amazon RDS with encryption at rest under an AWS KMS managed key. Uploaded files use S3 server-side encryption. All traffic to public endpoints, including between the browser and the platform, is encrypted with TLS.

Each organisation's data is isolated at the application layer. Service-to-service traffic is restricted to a private AWS VPC, with separate public and private subnets.

5. Backups

Backups are stored in the AWS Backup service and encrypted with an AWS managed key. Point-in-time recovery is enabled for Aurora and S3. Daily snapshots are retained for five weeks and weekly snapshots for fourteen months. Only Opper engineers can restore a backup.

6. Deletion

Deleting a project removes all associated traces and events. Setting retention to zero stops trace storage for new calls. Files are removed when the customer deletes them or when their expiry passes. On termination of the customer agreement, personal data is returned or deleted as set out in section 8 of the Data Processing Agreement.

7. Incidents and vulnerability reports

Opper notifies the customer of a personal data breach affecting their data without undue delay and within 48 hours of learning of it, as set out in section 3.2 of the Data Processing Agreement. Vulnerability reports go to privacy@opper.ai; the contact and policy are also published in security.txt.

8. Sub-processors

Opper is the single AI sub-processor for every model on the platform. The model providers behind each route, with their region, retention and training posture, are listed in the provider directory; the infrastructure services behind the platform are registered on the Opper trust center. Additions and replacements are notified as set out in section 4 of the Data Processing Agreement.

9. Certification and documents

Opper is certified against ISO/IEC 27001:2022. The controls and policies behind it are published on the trust center, where the certificate is available on request. The Data Processing Agreement is published on this site and we sign it on request, custom DPAs are available, Standard Contractual Clauses are available on request, and Enterprise agreements can extend zero retention to the usage metadata too. Every document is listed on the legal page.

The AI gateway for agents on any model. Built in Stockholm, hosted in the EU.

hello@opper.ai
ISO/IEC 27001:2022 certifiedGDPR compliant

Product

ModelsProvidersAppsChatRoundtableMedia StudioPricingEnterprise

Features

AI Control PlaneLLM GatewayLLM RouterAgent CLIOpper AccountSecurity & ComplianceSovereign AI

Developers

DocsAPI ReferenceMCP serverChangelogBlogCustomer storiesUptime & StatusContact

Compare

Compare modelsEU-hosted modelsLLM LeaderboardRelease trackerCar Wash Testjevman benchmarkOpper vs OpenRouterOpenRouter alternativesOpper vs LiteLLMBest AI gateways
© 2026 Opper Technology AB
LegalTerms of servicePrivacy policySecurity overviewTrust centerDPASubprocessorsllms.txt