Security
Written the way our threat model is written: what the boundary is, how it is enforced, and what is outside it.
The boundary: read-only, on both sides
The only actions any part of Operanse can take on your site are ten enumerated read capabilities: list plugins, read a setting by name from an allow-list, summarise the queue, and so on. There is no capability that runs SQL, PHP, shell or WP-CLI, no option update, no file write. The list is defined once in a contract and mirrored in the plugin; adding one requires a schema, limits, an audit event and both sides. A test asserts that no capability name contains a forbidden word.
The hosted service, the dashboard, the MCP server and the AI review all go through that list. An AI model never receives a tool that can change anything, because none exists to give it. Remediation, if it ever ships, is a separate approval service with separate credentials and its own decision record.
What never leaves your site
Telemetry is operational: ids, statuses, counts, amounts, currencies, durations, gateway ids, hook names, plugin slugs and versions. No names, emails, addresses, phones, visitor IPs, cookies, headers, session contents, card data, raw POST bodies, page URLs or referrers. The plugin runs a redactor over every free-text field before it is spooled (emails, card-like digit runs, bearer tokens, live keys, long secrets), and the service runs a second one on ingest. Both have fixture tests, and a change to either needs a note in the threat model.
Discovery never reads wp-config.php, environment files, keys, certificates, vendor/ or node_modules/. The PHP error log tail (Insight) reduces every path to a file name before redaction and keeps at most three samples per level.
Transport and credentials
Pairing uses a one-time token you paste into the plugin. The service mints a site id, a key id and a 256-bit secret, encrypted at rest with a master key; the token is invalidated. Every request the plugin makes is signed with that secret and bound to the API hostname, so a stolen signature cannot be replayed elsewhere. Nothing inbound is required: by default the plugin polls out, or holds an outbound stream. If you enable the inbound transport, its requests are signed the same way and reach only the same closed capability list.
Tenant isolation, in the database
Every tenant table carries an organisation id and a PostgreSQL row-level security policy that is forced on. Application queries run inside a tenant scope; the few places that look something up before a tenant is known (pairing, credential lookup, login) use a system scope that is audited. A new table does not ship without its policy and an isolation test.
AI, and what it is given
On Insight, a review receives labelled evidence records inside a delimited data block whose system prompt states that the content is data and cannot change instructions. Customer content is never interpolated into instructions. Output is validated: every observed fact and likely cause must cite an evidence id that exists in the input, or the review is rejected. Spend is bounded per site per day. The provider is Anthropic; the data sent is the redacted operational evidence above, never shopper personal information, and is not used to train models under our agreement.
Fail open
No Operanse failure may break WordPress or WooCommerce. The plugin makes no synchronous network call during a visitor’s request; events are spooled locally and uploaded later, with backoff, surviving days offline. Every collector runs under a guard that turns an exception into a reported gap. This was measured, not asserted: zero outbound calls attributable to the plugin in 200 front-end requests, against a control with the plugin deactivated.
Where it runs
DigitalOcean, New York. TLS at the edge with certificates from Let’s Encrypt; HSTS on every host. The dashboard, the API and the MCP server are separate processes on separate hostnames. Billing is Stripe Checkout and the Stripe customer portal; we hold no card data. Mail is sent through Mailgun. The full list is on the sub-processors page.
Reporting a vulnerability
Write to security@operanse.com. We acknowledge within two business days and keep you informed until it is fixed. Please do not test against stores that are not yours; a paired staging site of your own is free on every plan. Privacy questions go to privacy@operanse.com.