OPEXEngine Trust Center
At OPEXEngine, safeguarding the confidentiality, integrity, privacy and security of your data is our top priority. We adhere to industry standards and regulations to ensure robust protection and compliance.
FAQs
Resources
Controls
Sub-Processors
Letter of Attestation SOC 2 Type 1
SOC 2 Type 1 Report
SOC 2 Type 2 Report
FAQs
Frequently Asked Questions
Where does the data collected by OPEXEngine reside?
Data resides securely in the U.S. in Amazon's AWS data centers (US East Region) with strict
access controls in place.
Is customer data encrypted at rest? If yes, what type of encryption is in use?
Yes, all company and user-identifying data is encrypted at rest using an AES-256 encryption
algorithm with Salt. Passwords/tokens are encrypted one-way with SH13-256 encryption.
Is data encrypted in transit? If yes, how does OPEXEngine ensure that all transmissions are
secure?
All in-transit data transmissions are encrypted with SSL/TLS including web traffic and ssh
connections (ssh connections require a private key and a password on top). Our SSL/TLS key
type is RSA, 2,048-bit. SSL certificates are installed per public and private servers and SSL/TLS
connections are enforced from end-to-end.
Is any data stored locally on devices and can it be removed remotely?
No data is stored locally unless you choose to create and download a report. Such downloaded
reports cannot be removed remotely because BenchmarkEngine does not have an installable
client and thus does not have access to your device.
Does OPEXEngine share or sell any of their subscribers’ communications, data, or metadata?
OPEXEngine does not sell individual company data. OPEXEngine is a developer of anonymized,
aggregate benchmarks, based on the data from the participating companies. No one company
can see the data of another company, but every company’s depersonalized, blinded data
becomes part of the aggregate anonymized data set which is sold by OPEXEngine.
Who has access to the data collected by OPEXEngine?
Only your company’s authorized users have access to your data. The user access level is
determined by the access level/permissions assigned to the user. Also, authorized OPEXEngine staff may access certain company data as needed - such data access is logged, and audits are
performed regularly or as needed. No external persons, systems, or third parties have access
to your data.
Can accounts be managed by a single administrator?
Yes, there is a Company Admin user role that can manage all accounts for a subscribing
company.
How do we secure access from non-employees or unauthorized employees?
OPEXEngine will generate unique and secure logins for your users. Only credentialed users can
log into the BenchmarkEngine; a credentialed user is subject to email verification and multi-
factor authentication. Departed employees’ access is terminated by our Human Resources
Security procedures with the primary goal of protecting access to company and customer
assets.
OPEXEngine will notify the designated Company contact person every quarter to verify the
user list, ensuring that access to BenchmarkEngine is restricted for any employees not
affiliated with the company.
Does OPEXEngine use Multi-Factor Authorization (MFA) to validate authorized users?
Yes, OPEXEngine has implemented mandatory, email-based MFA to authenticate active users.
Is there a software client involved? If so, how disabled? access and content removed once an
account is disabled?
There is no client involved. Access is via a direct secure browser connection.