Available now
- Browser-local CSV/Excel analysis with explicit reviewed document extraction
- Published data-flow, Privacy Notice and Terms
- Hashed server-side sessions and expiring email codes
- Organisation RBAC and server-side membership checks
- OIDC Authorization Code + PKCE with signed-token verification
- Domain verification before domain-based JIT access
- Allowlisted shared structural memory and organisation/identity audit
- Local export/clear controls and AI context minimisation
- Durable per-account burst and hourly controls on AI-backed requests
Requires customer decision
- Whether the intended datasets are appropriate for the current beta posture
- Lawful basis and internal authorisation for personal data
- Which fields should be excluded, anonymised or treated as sensitive
- Organisation roles and whether SSO/JIT should be enabled
- Endpoint/device controls for browser-local source files and exports
- Whether Ask NaraOps may be used for the intended dataset
Not yet represented as certified
NaraOps does not currently claim ISO 27001, SOC 2, a formal penetration-test attestation, a 24/7 SOC, a contractual availability SLA, a certified 1,000-concurrent-user capacity, SAML, SCIM/directory synchronisation or managed-device controls unless separately completed and documented later.
Review route
Procurement or security teams can use this pack, the Security & Data Flow page, provider list, Privacy Notice and Terms, and can request a supplier-security questionnaire response or technical review. Source code is not publicly distributed as part of standard access; any deeper code or architecture review would need to be agreed separately.
Supplier overview
NaraOps is a UK-based business software service for operational analysis. The current beta uses browser-local processing for source operational files where possible and server-side services for account, access, organisation, SSO, billing-reference, feedback and AI-request handling.
Data categories
Browser-local: uploaded operational workspace data, actions, local structural mapping memory, proof-of-value information and local audit history may be retained on the device.
Server-side: account email, session/access records, trial/subscription status, feedback, limited billing references, organisation/member/invitation records, allowlisted shared structural memory, organisation audit events, OIDC SSO configuration/state/audit, time-windowed per-account AI request counters, limited account-level launch attribution/product-milestone records and ordinary technical/security metadata. Launch funnel records do not contain uploaded operational rows. Stale AI counter windows are opportunistically deleted as later AI requests are processed.
Ask NaraOps: compact analytical context generated from verified metrics and evidence; raw operational rows are not intentionally included.
Document extraction: a PDF, image or document selected by the user for extraction is sent to OpenAI for that request. NaraOps does not intentionally retain the original document in its account database; proposed extracted values stay behind local review and approval before analysis.
Authentication and sessions
Standard sign-in uses time-limited one-time email codes. Session tokens are random and stored server-side as hashes. The browser session cookie is HttpOnly, Secure and SameSite=Lax.
Organisation SSO uses OpenID Connect Authorization Code with PKCE. NaraOps stores short-lived hashed state references and a nonce/code verifier for the sign-in transaction, validates the provider issuer/audience/expiry/nonce, and verifies the ID-token signature against the provider JWKS before issuing a NaraOps session. Organisations may require SSO; enforcement occurs on the server so normal email-code endpoints cannot be used by eligible users while that policy is active.
Organisation isolation and RBAC
Organisation-scoped APIs verify both the signed-in user and membership of the requested organisation. Roles are Owner, Admin, Member and Viewer. Owner/Admin manage membership according to role boundaries; Members can contribute shared structural memory; Viewers have read-only access to shared organisation resources. The Owner cannot be removed or downgraded through the current member-management API.
Shared memory minimisation and audit
Company memory is restricted to structural metadata required to remember confirmed meanings and relationships. The server allowlists supported properties and discards unrelated properties before persistence. Source rows and field examples are not part of the shared-memory schema.
Server-side organisation audit events record organisation creation, invitations, invite acceptance, role changes, member removal, renaming and shared-memory updates. SSO configuration/domain verification and successful or failed SSO sign-ins are also recorded in an organisation-scoped identity audit.
Payments
Lemon Squeezy is merchant of record for subscription billing. NaraOps receives limited customer/subscription identifiers and entitlement/payment state; it does not receive or store full card numbers.
Subprocessors / service providers
Cloudflare — hosting, database, DNS lookup and edge/security services.
OpenAI — Ask NaraOps responses from compact analytical context.
Resend — sign-in, invitation and service email delivery.
Lemon Squeezy — merchant of record for subscription billing.
The customer's chosen OIDC identity provider processes authentication during SSO.
Retention and deletion
Browser-local NaraOps data can be exported or cleared by the user from Workspace. Server-side account, entitlement, organisation, SSO, billing-reference, feedback and security records are not removed by clearing browser data. Organisation deletion/self-service server-record deletion is not yet exposed in the beta UI.
Application and AI safeguards
Local-first source-file processing reduces centralised row-data storage. Sensitive-field controls protect broad analysis and AI context by default. Ask NaraOps applies a server-side context boundary and answer-integrity guards intended to withhold unsupported or role-swapped analytical claims. These controls reduce risk but do not replace customer endpoint security, authorisation, professional judgement or formal assurance testing.
Scale and availability
Core dataset analysis is distributed across user browsers rather than executed by one shared analytical server. Shared sign-in, organisation, entitlement and AI paths still depend on cloud/provider capacity. NaraOps has not yet represented a specific concurrency level or uptime target as certified; formal load testing and monitoring evidence should precede an enterprise capacity or SLA commitment.
Current limitations
The review beta is not yet intended for highly confidential data, special-category personal data, regulated personal data, credentials, secrets or workloads requiring enterprise controls beyond the current posture. SAML, SCIM/directory synchronisation, organisation ownership transfer and managed-device controls are not yet production features. OIDC providers that require a confidential-client secret are also not supported by the current secretless PKCE configuration.
DPIA support prompts
When assessing use of NaraOps, organisations should document: the operational datasets they intend to use; whether personal data is present; the lawful basis for that processing; whether fields should be excluded or anonymised; which Organisation roles are appropriate; whether SSO will be enforced; whether verified-domain JIT should be enabled; who may access source files on local devices; whether Ask NaraOps will be used; retention expectations; and whether the current beta posture is appropriate for the sensitivity of the information.
Incident and privacy contact
Privacy and security questions can be sent to privacy@naraops.com. See the Privacy Notice, Security & Data Flow and Terms.