TRUST / SECURITYSecurity and privacy

See how Opselith handles your data.

Core tools keep working data in your browser. Opselith does not connect to your Microsoft tenant or store tenant credentials.

DATA FLOW

What leaves your browser?

Most working data stays in your browser. Scan the boundaries below and open Technical details only when you need the full behavior.

Core working dataBrowser-local
Tenant connectionNone
Raw search textBrowser-local
Core accountNot required

Core browser tools

CSV, list comparison, conversion, migration mapping, passwords, naming and JWT tools.

ProcessingBrowser-local
SendsAnonymous usage count
StoredNo working data
Technical details

Working data: Files, pasted values and generated results stay in the active page.

Request: Allowlisted tool/action signals may be sent after supported actions.

Storage: No file contents, filenames, input values or generated output are stored; only aggregate usage counts.

Search & script discovery

Global search, Command Center and PowerShell search.

ProcessingSearch text stays local
SendsSafe anonymous signals
StoredDaily totals only
Technical details

Working data: Search text is privacy-filtered in the browser before telemetry is considered.

Request: Only allowlisted generic IT/admin terms, result outcome or a published script ID/source can be sent.

Storage: Raw search text is not stored. Searches without a safe term become a privacy-withheld marker.

Free PowerShell Builder

Free script generation.

ProcessingBrowser-local generation
SendsAnonymous usage signals
StoredNo script history
Technical details

Working data: Configuration values and the generated PowerShell script are built in the browser.

Request: Usage and published-script open signals may be sent.

Storage: Generation values and generated Free scripts are not stored by Opselith. Local preferences can remain in your browser.

Pro / tester PowerShell generation

Access-controlled generation.

ProcessingOpselith generation service
SendsKey + generator values
StoredEntitlement state only
Technical details

Working data: The Access Key, selected template/target and required generator values are sent to Opselith after you choose Generate.

Request: The service verifies entitlement, validates the request and returns the generated script.

Storage: Opselith maintains access/entitlement records. Generator values and returned scripts are not added to anonymous analytics or a user script-history account.

Saved in this browser

Favorites, recent work, saved configurations, workflow progress, migration projects and activated key.

ProcessingThis browser
SendsAccess key when checked
StoredNo cloud profile
Technical details

Working data: Convenience features and Migration Workspace project metadata are stored on the device/browser you are using. Migration projects can include organization names, source/target domains, selected workloads, readiness summaries, migration-wave summaries and manual readiness confirmations, but not raw mapping, Exchange recipient or migration-wave user rows.

Request: A saved Access Key is re-sent when access is verified. Other local preferences do not need an account.

Storage: Opselith does not create a cloud profile for these preferences. Supported workspace data can be exported or restored locally; that export excludes the saved Pro/tester key and generated PowerShell scripts. Lock Pro access removes the saved key from this browser.

Tester submissions

Invited tester flow only.

ProcessingFields you choose
SendsTest report
StoredSubmitted report only
Technical details

Working data: Structured test results and feedback are intentionally submitted for product validation.

Request: The tester key is checked before the form can submit.

Storage: Report fields are retained for product-quality review. The raw tester key and requesting IP are not stored with the report.

Public Pro sales are currently closed. Core tools do not require a payment flow. External providers are involved only when you deliberately use a feature that depends on them.

More security details

Local processing

Data used by the core CSV, list-comparison, conversion, migration-mapping, password, JWT and naming tools is processed in the active browser session. There is no customer database behind these tools. Opselith does record anonymous aggregate tool-usage counters - for example, how often a tool action is used - without storing identities, IP addresses, filenames, input values or generated output. A Cloudflare-provided IP address may be used transiently only to rate-limit anonymous usage requests; it is not written to the Opselith usage database.

No account layer

You can use the core tools without creating an account, signing in or giving Opselith tenant credentials.

No file-upload backend

The core toolkit does not upload your working files to Opselith. This is a deliberate architectural choice for administrator workflows that may contain sensitive operational data.

Strict browser controls

The production site uses a restrictive Content Security Policy and related security headers to reduce the attack surface of the browser-facing application and its edge delivery layer.

Limited request sizes

Endpoints that accept browser or webhook payloads enforce explicit request-size limits before parsing. Pro operations use a separately tunable rate-limit boundary so abuse controls do not depend on the anonymous usage-counter limits.

Scoped Pro access

Access Keys are validated server-side against active entitlements. Newly issued keys carry an opaque identifier rather than a payment-provider customer reference, and Pack-only access does not unlock unrelated Pro scripts or Packs.

Release supply chain

Release workflows pin third-party artifact actions to immutable commit references and pin the versions of the release tools used by the validation pipeline. This reduces unintended changes from mutable CI dependency tags.

Transparent PowerShell output

Free PowerShell templates are generated in the browser. Pro templates are generated by Opselith after server-side license validation. In both cases, the generated script is shown for review before you copy or run it. Read-only and change-making templates are explicitly classified.

Responsible disclosure

If you discover a security issue, email support@opselith.com. Do not include passwords, access tokens, private keys or personal data in the first report.

How local processing works
WHAT LOCAL MEANS

Your browser is the processing layer.

For the core tools, Opselith acts as a static application delivered to your browser. When you paste data or select a file, the JavaScript running in your browser performs the conversion, inspection or generation. The result stays in the page until you copy it, download it or otherwise move it yourself.

That does not mean every surrounding service on the internet is invisible: your browser still communicates with the hosting provider to load the site. Opselith also sends a minimal same-origin usage event when a tool is opened or a supported action succeeds; that event contains only an allowlisted tool name and action. External services you deliberately open, such as a payment provider, have their own privacy policies. The important distinction is that the core tool workflow does not require uploading your working data to an Opselith processing service.

LIMITS

Security is a process, not a promise.

Local processing reduces a major class of data-transfer risk, but it does not make generated scripts automatically safe. Always review PowerShell before execution, validate third-party input, use least privilege and test changes outside production.

Does Opselith upload my files?

The core browser tools process selected files locally and do not provide an Opselith file-upload backend. Anonymous usage statistics never contain file contents. The usage endpoint uses a transient rate-limit key to reduce automated spam; that key is not stored in Opselith statistics.

Does Opselith require an account?

No. The core tools are designed to work without an account or sign-in. Usage statistics do not create a user profile.

Does the JWT Decoder verify signatures?

No. It decodes and inspects token structure and claims. A decoded JWT is not proof that the token is authentic.

How should I report a vulnerability?

Email support@opselith.com with concise reproduction details. Do not send secrets or personal data in the initial message.