Opsidian
Privacy

What we collect, and what we do not

Opsidian is a security intelligence platform used by named analysts inside a workspace. This notice covers the public website and the product, and it describes what the software actually does.

Last updated: September 7, 2026

Who is responsible

Opsidian operates this website and the platform. For anything in this notice, including access, correction and erasure requests, write to contact@opsidian.eu and we will answer within one month.

The public website sets no cookies

Browsing the marketing pages, the risk check on them, this notice and the support page sets no cookie of any kind. There is no analytics, no advertising, no tag manager and no third-party tracker anywhere on the site, so there is nothing to consent to and no banner to dismiss. Our servers keep short-lived technical logs of requests, which our hosting providers retain on our behalf and which we use only to keep the service running and to investigate abuse.

The risk check

  • The risk check asks for nothing about you and keeps nothing you answer. Your three answers are matched against our scenario library in memory, the result is returned to your browser, and none of it is written down.
  • The one thing we do store is a truncated, hashed version of your IP address, kept for a few minutes so the check cannot be run thousands of times from one place. The address is cut short before it is hashed, so it identifies a network neighbourhood rather than a household, and the original is never written down. The lawful basis is our legitimate interest in keeping an open endpoint available.
  • If you ask us for a demo from the result, that goes through the request form described in the next section, and nothing from your risk check travels with it unless you write it in the message yourself.

Requesting a workspace or contacting support

When you send a request through the site we receive your name, organisation, email and whatever you write in the message, and we use it to answer you and to set up an account if that is what you asked for. The lawful basis is our legitimate interest in responding to a business enquiry, and taking steps at your request before a contract. We keep these messages for as long as the commercial conversation is live, and for 24 months afterwards.

Inside the product

  • A workspace holds what its analysts put in it: entities, investigations, events, intelligence sources, documents and the audit trail of who did what. That content belongs to the customer, who decides what goes in it and for how long; we process it on their instructions.
  • Account data covers your name, email, role, workspace membership, notification preferences and multi-factor enrolment.
  • Signing in sets a session cookie. It is strictly necessary, it carries no advertising or analytics identifier, and it is what keeps you signed in between pages.
  • We keep an audit record of security-relevant actions, which is a control our customers rely on and which we do not switch off on request.

Where it is processed, and by whom

  • Database, authentication and file storage: Supabase, in the European Union (Frankfurt).
  • Application hosting: Vercel.
  • Email delivery: Microsoft 365, for the messages this notice describes.
  • Optional AI features: when a workspace turns them on, the text needed for that task is sent to Anthropic or OpenAI. It is not used to train their models. A workspace can use its own API key instead, or leave these features off, in which case nothing is sent.
  • Optional public data lookups: when a workspace runs a due diligence check, we query public and commercial sources such as GLEIF, OpenSanctions and search providers with the subject name that workspace entered.
  • Where a provider processes data outside the European Economic Area, the transfer relies on the European Commission standard contractual clauses.

Your rights

You can ask for a copy of what we hold about you, have it corrected or deleted, object to or restrict how we use it, withdraw consent, and receive it in a portable form. Write to contact@opsidian.eu. If you are unhappy with our answer you can complain to your national data protection authority; in France that is the CNIL. If your data is in a customer workspace rather than in our own records, we will point you to that customer, who decides what happens to it.

Security

Data is encrypted in transit and at rest. Access inside a workspace is enforced in the database itself, row by row, not only in the interface. Administrators are required to use multi-factor authentication. Our security practices are described in more detail on the controls section of the home page.

Changes

When this notice changes materially we update the date at the top and, where the change affects mail you receive from us, we say so in that mail. This version reflects the software as it stands on the date shown.

Need a contractual version?

Signed order forms, DPAs, and procurement exhibits govern when they differ from public summaries.

Contact us