Trust Centre

Understand exactly where your data goes.

Plain-English answers for managers, IT, security and procurement.

Current beta posture · 21 September 2026

Spreadsheet analysis is local-first; document extraction is explicit. NaraOps parses and analyses CSV and Excel operational files in the browser. A PDF, image or document is sent to OpenAI only when the user explicitly chooses Extract, and extracted values stay behind a review-and-approval gate before analysis. Ask NaraOps receives compact analytical evidence rather than raw operational rows.
What stays on this deviceCSV and Excel source rows, the saved local workspace, approved extracted records, local actions, folder permission handles/import ledgers, proof-of-value settings and local structural memory can remain in browser storage on the user's device.
What reaches NaraOps servicesAccount/session data, entitlement and limited billing references, organisation controls, feedback, compact Ask NaraOps analytical context and a document selected for explicit extraction are processed server-side where needed.
External providersCloudflare supports hosting/infrastructure, Resend email delivery, Lemon Squeezy subscription billing and OpenAI supports Ask NaraOps plus user-requested document extraction.

Payments

Checkout and subscription management are handled by Lemon Squeezy as merchant of record. NaraOps receives limited identifiers and subscription/payment state needed to grant access; NaraOps does not receive or store your full card number.

Scale & availability

Core operational analysis runs in each user's own browser, so one user's dataset analysis is not performed by one central analytical worker shared with every other customer. Shared services such as sign-in, entitlement, organisation APIs and Ask NaraOps still have normal service-provider and concurrency dependencies.

NaraOps has not yet formally load-tested or certified 1,000 simultaneous active users. The local-first architecture reduces shared compute pressure, but it is not a claim of certified capacity at that concurrency level. Formal load testing remains part of production hardening before any enterprise capacity commitment.

Security review

Source code is not publicly distributed as part of the standard product. A company reviewing NaraOps can use the Security & Data Flow page, Security Pack, privacy notice, terms, provider list and documented controls, and can request a technical review or supplier-security questionnaire response. NaraOps should not claim a certification, penetration test or control that has not actually been completed.

Ask NaraOps & document extraction

For Ask NaraOps, the browser prepares compact analytical evidence from the current workspace; raw operational rows are not intentionally included. Document extraction is a separate, explicit action: the selected PDF, image or document is sent to OpenAI for extraction, NaraOps does not intentionally store the original in its account database, and proposed values cannot affect analysis until the user reviews and approves them. Both AI-backed paths use durable per-account burst and hourly controls to reduce accidental loops, automated abuse and unexpected provider-cost spikes.

Company controls

Organisation membership, roles, invitations, allowlisted shared structural memory, SSO configuration and central organisation/identity audit events are server-side and scoped to the selected organisation. Source CSV/Excel workbooks and saved operational workspaces remain local to the user's browser; selected documents leave the browser only for an explicit extraction request.

Legal and decision risk

NaraOps is decision-support software, not a substitute for professional judgement. Current beta Terms, Privacy Notice and usage limits are published. More detailed enterprise contracting, liability allocation, insurance evidence or a customer-specific DPA should only be represented as available once actually reviewed and agreed.

What is stored by the service?

Account, access, feedback and subscription information are stored so NaraOps can operate your account. If you use an Organisation, NaraOps also stores membership, roles, invitations, allowlisted structural memory, SSO configuration and organisation audit events. Browser storage may hold your local workspace, actions and value-tracking settings on your device.

What should I upload during beta?

Use data you are authorised to use. During the current beta, avoid highly confidential information, special-category personal data, credentials, secrets or data that requires controls beyond the present beta security posture.

Procurement evidence

For a more technical view, read Security & Data Flow and the Security Pack. They describe authentication, organisation boundaries, SSO, providers, current controls, deletion/retention boundaries, limitations and review prompts. The full Privacy Notice and Terms are also available. Privacy and security enquiries can be sent to privacy@naraops.com.