TRUST / SECURITYSecurity and privacySee how Opselith handles your data.
Core tools keep working data in your browser. Opselith does not connect to your Microsoft tenant or store tenant credentials.
More security details
Local processing
Data used by the core CSV, list-comparison, conversion, migration-mapping, password, JWT and naming tools is processed in the active browser session. There is no customer database behind these tools. Opselith does record anonymous aggregate tool-usage counters - for example, how often a tool action is used - without storing identities, IP addresses, filenames, input values or generated output. A Cloudflare-provided IP address may be used transiently only to rate-limit anonymous usage requests; it is not written to the Opselith usage database.
No account layer
You can use the core tools without creating an account, signing in or giving Opselith tenant credentials.
No file-upload backend
The core toolkit does not upload your working files to Opselith. This is a deliberate architectural choice for administrator workflows that may contain sensitive operational data.
Strict browser controls
The production site uses a restrictive Content Security Policy and related security headers to reduce the attack surface of the browser-facing application and its edge delivery layer.
Limited request sizes
Endpoints that accept browser or webhook payloads enforce explicit request-size limits before parsing. Pro operations use a separately tunable rate-limit boundary so abuse controls do not depend on the anonymous usage-counter limits.
Scoped Pro access
Access Keys are validated server-side against active entitlements. Newly issued keys carry an opaque identifier rather than a payment-provider customer reference, and Pack-only access does not unlock unrelated Pro scripts or Packs.
Release supply chain
Release workflows pin third-party artifact actions to immutable commit references and pin the versions of the release tools used by the validation pipeline. This reduces unintended changes from mutable CI dependency tags.
Transparent PowerShell output
Free PowerShell templates are generated in the browser. Pro templates are generated by Opselith after server-side license validation. In both cases, the generated script is shown for review before you copy or run it. Read-only and change-making templates are explicitly classified.
Responsible disclosure
If you discover a security issue, email support@opselith.com. Do not include passwords, access tokens, private keys or personal data in the first report.
How local processing works