Security and privacy

Sign-in that is hard to abuse and easy to live with

Your plans, tickets and people are business information. Here is what protects them, in plain language.

Signing in

Passkeys

Sign in with a fingerprint, face or PIN, with no password to steal. Works with any provider, and skips the code.

Two-step sign-in

An authenticator app and recovery codes. It is asked only on a new device, and a device stays trusted for 30 days of use. Administrators can be required to use it.

Password reset

The link goes only to the account's own email, works once, expires in an hour, and the page never reveals whether an address has an account.

Lockout and limits

Wrong codes count towards the same lockout as wrong passwords, and repeated attempts from one address are slowed down.

Sessions

Idle for 2 hours and the session ends. Signing in somewhere else ends the older one.

If something goes wrong

An administrator's reset also removes passkeys and trusted devices, so a stolen password does not persist.

Your data

Customers are separated

Every query is filtered by team, and organisations never see each other. Roles are enforced on the pages themselves, not just by hiding menu items, and automated tests pin the role each sensitive page requires.

Secrets are encrypted

The access tokens and email keys teams store are encrypted in the database, so a copy of the database alone does not reveal them.

Safe content

Comments and imported ticket text are cleaned of anything that could run, spreadsheet exports neutralise formulas, and attachments always download rather than open.

Trust and accountability

Edits are protected

Concurrent edits are refused rather than silently overwritten, and meeting notes can be changed only by their author, with history kept.

Support is open

Signing in as a customer needs a reason, shows a banner, ends after 90 minutes, and everything changed is recorded and shown to the customer.

Registration needs approval

Anyone can ask for an account, and nobody gets in until it is approved. The email address is confirmed first.

TeamOps is hosted on Microsoft Azure. If you have security questions or want our answers in writing for your own review, get in touch.