Opiniion, Inc. | Trust Center

Trust you can see, built into every layer.

Your residents trust you with their home. You should be able to trust your software. Opiniion's security controls are independently audited and continuously monitored, protecting resident data at every step from tour to move-out.

Compliance

SOC 2 Type 1

SOC 2 is the AICPA standard for how service organizations protect customer data. Our Type 1 audit verified the design of our security controls across the Security Trust Service Criteria.

Monitoring

Continuously monitored by Secureframe

Resources

SOC 2 Type 1 Report

Our SOC 2 Type 1 report, completed by an independent auditor, covering the design of our security controls. Available on request under NDA. - Updated Jun 29th, 2026

Information Security Policy

The parent policy governing information security at Opiniion, covering data protection, access control, and security responsibilities. Available under NDA. - Updated July 23rd, 2026

Opiniion Security Overview

A one-page summary of how Opiniion protects resident and customer data. Free to download and share - Updated August 5th, 2026

Security Incident Response Plan

Our published incident response plan (v2.0). Severity classification, response time targets, containment, evidence preservation, customer notification, and post-incident review. SOC 2 mapped.

Subprocessors

AWS

Amazon Web Services (AWS) provides cloud computing infrastructure and services including compute (EC2), storage (S3), databases (RDS, DynamoDB), networking, machine learning, analytics, security, and developer tools. AWS is used as the primary cloud infrastructure provider.

Data location: United States (us-east-1, us-west-1)

Anthropic

AI safety research and large language model (LLM) API services, including the Claude family of AI models (Claude API, Claude Enterprise, Claude Team). Anthropic provides AI-powered text generation, analysis, coding assistance, and conversational AI capabilities for enterprise and developer use cases.

Data location: United States

ClickUp

Project management and productivity platform providing tasks, docs, whiteboards, chat, goals, and AI-powered collaboration tools for teams of all sizes.

Data location: United States

Databricks

Databricks provides a unified Data Intelligence Platform built on open lakehouse architecture. Services include data engineering, data warehousing, data streaming, machine learning, AI model development, and data governance. The platform enables organizations to unify all their data and AI workloads on a single platform powered by Apache Spark, Delta Lake, MLflow, and Unity Catalog.

Data location: United States (us-east-1, us-west-2)

Github

Code Repository

Data location: United States

Google Cloud

Cloud computing infrastructure and services

Data location: United States

Google Workspace

Identity, Mail, Storage

Data location: United States

HubSpot

HubSpot is a CRM platform that provides software and tools for marketing, sales, customer service, and content management. Services include email marketing, marketing automation, sales pipeline management, customer support ticketing, live chat, CMS hosting, and analytics.

Data location: United States

Fivetran

Fivetran is an automated data movement platform that provides fully managed ELT (Extract, Load, Transform) pipelines. It connects data sources (databases, SaaS applications, files, events) to cloud data warehouses and data lakes, enabling teams to centralize and analyze their data. Fivetran handles schema changes, data normalization, and keeps pipelines running reliably without manual maintenance.

Data location: United States (us-east-1)
View all

FAQs

Yes. We completed a SOC 2 Type 1 audit with an independent auditor, and our controls are monitored continuously through Secureframe. Our report is available on request.
All customer data is hosted in the United States on AWS, with encryption in transit and at rest.
We process resident contact information and feedback data (surveys, reviews, sentiment) on behalf of our property management customers. We only collect what's needed to deliver the platform.
No. Customer and resident data is used only to provide the service. We never sell it.
Our AI analyzes resident feedback to surface patterns and recommend next steps. It works within our secured environment, and your data is never used to train third-party models.
Email our security team and we'll respond quickly. [email protected]
Yes. Our SOC 2 Type 1 report is available under NDA. Click Request on the report above and we'll review your request promptly.
Yes. We support vendor security questionnaires for active evaluations. Reach out to your account executive or contact [email protected].

Security at Opiniion

Questions, or found something we should know about?

Reach our security team directly at [email protected]. We review every report and respond promptly. Good-faith security research is always welcome.

Documents provided through this page are confidential and subject to your NDA or agreement with Opiniion.

Monitoring

Access Security

User Access Reviews
System owners conduct scheduled user access reviews of production servers, databases, and applications to validate internal user access is commensurate with job responsibilities.
Encryption and Key Management Policy
An Encryption and Key Management Policy supports the secure encryption and decryption of app secrets, and governs the use of cryptographic controls.
Access to Product is Restricted
Non-console access to production infrastructure is restricted to users with a unique SSH key or access key
Unique Access IDs
Personnel are assigned unique IDs to access sensitive systems, networks, and information
Access Control and Termination Policy
An Access Control and Termination Policy governs authentication and access to applicable systems, data, and networks.

Network Security

Network Security Policy
A Network Security Policy identifies the requirements for protecting information and systems within and across networks.
Automated Alerting for Security Events
Alerting software is used to notify impacted teams of potential security events.

Vulnerability Management

Vulnerability and Patch Management Policy
A Vulnerability Management and Patch Management Policy outlines the processes to efficiently respond to identified vulnerabilities.

Incident Response

Incident Response Plan
An Incident Response Plan outlines the process of identifying, prioritizing, communicating, assigning and tracking confirmed incidents through to resolution.
Incident Response Plan Testing
The Incident Response Plan is periodically tested via tabletop exercises or equivalents. When necessary, Management makes changes to the Incident Response Plan based on the test results.

Change Management

Segregation of Environments
Development, staging, and production environments are segregated.
Secure Development Policy
A Secure Development Policy defines the requirements for secure software and system development and maintenance.
Change Management Policy
A Change Management Policy governs the documenting, tracking, testing, and approving of system, network, security, and infrastructure changes.
Production Data Use is Restricted
Production data is not used in the development and testing environments, unless required for debugging customer issues.
Baseline Configurations
Baseline configurations and codebases for production infrastructure, systems, and applications are securely managed.
Configuration and Asset Management Policy
A Configuration and Asset Management Policy governs configurations for new sensitive systems

Availability

Testing the Business Continuity and Disaster Recovery Plan
The Business Continuity and Disaster Recovery Plan is periodically tested via tabletop exercises or equivalents. When necessary, Management makes changes to the Business Continuity and Disaster Recovery Plan based on the test results.
Uptime and Availability Monitoring
System tools monitors for uptime and availability based on predetermined criteria.
Backup Restoration Testing
Backed-up data is restored to a non-production environment at least annually to validate the integrity of backups.
Business Continuity and Disaster Recovery Policy
Business Continuity and Disaster Recovery Policy governs required processes for restoring the service or supporting infrastructure after suffering a disaster or disruption.

Risk Assessment

Vendor Due Diligence Review
Vendor SOC 2 reports (or equivalent) are collected and reviewed on at least an annual basis.
Vendor Risk Assessment
New vendors are assessed in accordance with the Vendor Risk Management Policy prior to engaging with the vendor. Reassessment occurs at least annually.
Vendor Risk Management Policy
A Vendor Risk Management Policy defines a framework for the onboarding and management of the vendor relationship lifecycle.
Risk Register
A risk register is maintained, which records the risk mitigation strategies for identified risks, and the development or modification of controls consistent with the risk mitigation strategy.
Risk Assessment and Treatment Policy
A Risk Assessment and Treatment Policy governs the process for conducting risk assessments to account for threats, vulnerabilities, likelihood, and impact with respect to assets, team members, customers, vendors, suppliers, and partners. Risk tolerance and strategies are also defined in the policy.
Risk Assessment
Formal risk assessments are performed, which includes the identification of relevant internal and external threats related to security, availability, confidentiality, and fraud, and an analysis of risks associated with those threats.

Confidentiality

Data Classification Policy
A Data Classification Policy details the security and handling protocols for sensitive data.
Access to Customer Data is Restricted
Access to, erasure of, or destruction of customer data is restricted to personnel that need access based on the principle of least privilege.
Data Retention and Disposal Policy
A Data Retention and Disposal Policy specifies how customer data is to be retained and disposed of based on compliance requirements and contractual obligations.