Security
Security notes for early access.
OpsProbe is designed as a standardized monitoring SaaS. The first version keeps the security model small, auditable, and focused on account isolation.
Account access
Users sign in with Google OAuth. Sessions are stored server-side and scoped to workspace membership.
Data access
Workspace, site, and monitor APIs require an authenticated session or authorized API token. Token secrets are stored as hashes, not plaintext.
Scanning approach
OpsProbe will use standard scan profiles rather than custom enterprise rule sets. Deeper security checks will be added gradually with clear limits and ownership verification.