01Credentials stay server-side
OPERA Cloud authentication runs from the application server using your environment’s own client credentials. The browser never holds a token or calls Oracle directly, so nothing sensitive is exposed to the client session.
02We use the access you grant
Imports run only against OPERA environments you configure and authorise. There is no back door, no shared tenancy of your property data, and no write path outside the environments you have set up.
03Nothing goes live unannounced
Workbook Studio never writes to OPERA at all. In Configurator, validation runs check-only, and a live import is an explicit action against a named environment.
04Guest data only where it is needed
Migration works on the extracts your project requires, for the cutover it is scoped for. Preparation work in Workbook Studio uses configuration data, not guest records.
05An audit trail you can produce
Every imported row is logged with its outcome and the identifier OPERA returned. If someone asks what was written and when, there is a record rather than a recollection.
06Deployment that fits your policy
The applications are ordinary Node.js and MySQL services. Where your policy requires it, they can run inside your own environment rather than ours. Confirm hosting arrangements during scoping.
This page describes how the applications are built and operated. It is not a certification claim, and it does not replace your own due diligence or a data processing agreement. We are glad to complete your security questionnaire.