Security & Trust

Built for clusters you're not allowed to break.

OptOps is designed for BFSI, gov-tech, and regulated environments — where trust has to be enforced by architecture, not promised in a slide deck.

Default at install

OptOps observes. Nothing changes.

OptOps can

  • check_circleCollect metadata and utilization metrics
  • check_circleCompute cost breakdowns and savings estimates
  • check_circleSurface rightsizing and consolidation recommendations

OptOps cannot

  • cancelMutate any workload or node
  • cancelRead secrets, env vars, or workload data
Effective permissions:getlistwatch

Click through the stages — this is exactly how a rollout goes.

The data boundary

Your security review will ask. Here's the answer up front.

outboundCollected (metadata only)

  • check_circleWorkload names, kinds, and resource requests/limits
  • check_circleCPU, memory, and utilization metrics
  • check_circleNode types, instance classes, and pricing signals

blockNever collected

  • cancelSecrets and ConfigMap contents
  • cancelEnvironment variables
  • cancelApplication data, logs, or request payloads

And the decisions themselves? Made by the engine running inside your cluster — not by a SaaS control plane reaching in from outside.

Verified, not asserted

workspace_premium

Independently assessed

The platform has completed an independent third-party application security assessment, and ISO certification is in progress.

fmd_bad

Fail-open everywhere

Every webhook is fail-open by design: if OptOps ever goes down, your cluster schedules exactly as it did before we arrived.

history

Full auditability

Every action the platform takes is logged with what changed, when, and why — built for change-management and audit reviews.

Bring your security team to the demo

We'll walk through the agent's permissions, the data that leaves your cluster (metadata only), and the audit trail — question by question.

Book a Demo
Calculate ROI