1What is Opsiton?
Opsiton is a modern, dual-layer endpoint Data Loss Prevention (DLP) platform. It prevents confidential and regulated data from leaving corporate devices — across web browsers, desktop applications, developer IDEs, and command-line terminal tools.
Dual-Layer Architecture
- 1Central Management: Administrators define and publish security policies from the Tenant Portal
- 2Native Endpoint Agent: A lightweight Rust daemon (with WFP driver on Windows or Network Extension on macOS) intercepts system traffic and terminal commands
- 3Browser Extension: Deep DOM and UI interception inside Chrome, Edge, and Brave for instant user warnings and block screens
- 4Local Transparent Proxy: Enforces real-time DLP inspection at 127.0.0.1:44443 with sub-15ms latency
- 5Real-time Visibility: Sanitized security events and incidents sync to the Opsiton portal for audit and investigation
What Opsiton Detects
- Sensitive text typed into web forms and chat inputs
- Credit card numbers validated via Luhn checksum algorithm
- TCKN and Turkish IBAN validated with algorithmic modulus checks
- File uploads inspected by MIME type, extension, and full text extraction (PDF, DOCX)
- Turkish and English OCR extraction from uploaded image files
- Data pasted into GenAI platforms (ChatGPT, Claude, Gemini, Copilot, DeepSeek, Perplexity)
- Visits to malicious, phishing, or unapproved threat URLs
- Terminal commands and desktop application network exfiltration
2Platform Components
| Component | Target Surface | Purpose |
|---|---|---|
| Tenant Portal | Admins & Security Teams | Central web console (bs-portal.opsiton.com) to manage policies events incidents users and deployment |
| Native Endpoint Agent | macOS & Windows Devices | High-performance Rust core that runs transparent proxy inspection and enforces policies locally |
| Browser Extension | Chrome Edge Brave Chromium | Intercepts paste drag-and-drop form submissions and delivers in-browser warn/block dialogs |
| Local Transparent Proxy | Local Loopback (127.0.0.1:44443) | System-wide inspection gate for desktop apps IDEs and terminal utilities outside the browser |
| Super Admin & Telemetry | Platform Operators | Central health telemetry (bs-admin.opsiton.com) monitoring agent fleet latency and performance |
3Privacy & Zero-Data-Exfiltration Architecture
Opsiton is architected on a strict Zero-Data-Exfiltration model. Your sensitive files, confidential prompts, and private customer records never leave the local endpoint to Opsiton cloud servers.
- On-Device Inspection: All regex matching, Luhn checksums, OCR parsing, and GLiNER NER model evaluations execute 100% locally on the device CPU/GPU
- Sanitized Event Telemetry: When a policy violation occurs, Opsiton transmits only sanitized metadata: rule name, timestamp, domain/application name, severity, and a SHA-256 content hash with masked snippet
- Zero Plaintext Storage: Neither the portal nor Opsiton cloud databases ever receive or store the raw sensitive data.
4Fail-Safe Architecture: Fail-Open vs. Fail-Closed (REQ-PRX-001)
An IT buyer's primary reliability question is: "What happens if your agent crashes or the daemon stops?" Opsiton operates under a formal fail-safe contract (REQ-PRX-001) that transparently balances non-disruptive business operations against zero data compromise.
Target vs. General Traffic Contract
| Traffic Category | Agent Healthy | Agent Stopped / Degraded | Rationale & Enforcement |
|---|---|---|---|
| Admin-Targeted Risk Domains (ChatGPT Claude Gemini etc.) | Transparent MITM Inspection & Policy Enforcement | Fail-Closed (Immediate Connection Drop) | Prevents confidential data leakage when inspection engine is unavailable |
| General Business Traffic & Non-Risk Websites | Inspected or Direct Routing | Fail-Open (Direct Connection) | Prevents enterprise network outages; an unhealthy agent is an IT ticket not a company blackout |
| Direct Exemption Domains & OS Infrastructure | Direct Bypass Route | Fail-Open (Direct Connection) | Preserves OS updates Apple APNs MDM commands and enterprise internal systems |
Enterprise Norm & Empirical Verification
- Industry Standard: Leading enterprise DLP and network security products (Forcepoint "no policies are enforced", GlobalProtect default fail-open) establish that endpoint security must not turn into a single point of operational network failure.
- Empirical Live Verification: Validated on live Chrome and Safari sessions — when the Opsiton daemon is stopped, admin-monitored AI endpoints (chatgpt.com) are instantly dropped (fail-closed) while corporate web tools remain accessible (fail-open).
- Automated IT Visibility: When an agent stops or loses policy synchronization, it reports a degraded status to the central portal and triggers IT diagnostics without disrupting end-user workflows.
5User Roles & Access Control
Access to the Tenant Portal is governed by role-based access control (RBAC):
| Role | Permissions |
|---|---|
| Viewer | Read-only access to security events incidents active users policies and reports |
| User | Standard employee access with view permissions and self-service status checks |
| Tenant Admin | Full administrative authority: create/edit policies invite members manage API keys deploy agents and manage subscriptions |
6Tenant Onboarding & Quick Start
Step 1: Register Your Organization
Visit the Tenant Portal (bs-portal.opsiton.com) and click Get Started or Register. Enter your full name, organization name, corporate work email, and secure password.
Step 2: Onboarding Setup
- 1Create your first DLP policy from verified compliance templates (e.g. Credit Card Luhn, TCKN, AI Platform)
- 2Obtain your fleet Enrollment Token from the Agent Deployment page
- 3Deploy the Opsiton Agent via MSI/PKG or MDM profiles with Chrome/Edge extension force-installation
- 4Verify live connection on the Dashboard
7Security Operations Dashboard
The Dashboard provides real-time situational awareness across your entire organization.
Security Posture Score
A dynamic 0-100 score quantifying fleet security health. The score decreases with unaddressed high-severity events and open incidents, and recovers as incidents are investigated and resolved.
Live KPI Cards
| Card | Metrics Shown |
|---|---|
| Portal Users | Active security team members with portal access |
| Application Users | Total enrolled endpoint devices and real-time online count |
| Active Policies | Number of enabled DLP, AI, and Threat URL rules |
| Events 24h | Total security detections recorded over the last 24 hours |
| Open Incidents | Unresolved security cases requiring triage and investigation |
8Policy Management & Enforcement
Policies dictate what data patterns to detect and what enforcement action to take when an employee interacts with sensitive data.
Enforcement Actions
| Action | User Experience & System Behavior |
|---|---|
| Block | Immediately terminates the transfer. Displays an instant full-screen or toast block dialog with the violation justification. |
| Warn | Displays an interactive warning dialog showing risk details. The user must provide a business justification to proceed or cancel the action. |
| Log | Silently allows the action while recording an audit event in the portal for security analysis. |
| Mask | Automatically redacts sensitive tokens (e.g. masking credit card or identity numbers with asterisks) before transmission. |
Built-in Rule Templates
- Payment Cards (Luhn Algorithm checksum verification)
- TC Kimlik No (11-digit modulus verification)
- Türkiye IBAN (ISO 7064 MOD 97-10 checksum)
- Turkish Mobile & Landline Phone Numbers
- Email Addresses & Confidential Token Patterns
- GDPR, KVKK, and PCI-DSS Compliance Frameworks
9Policy Types & Detection Engines
Opsiton features six specialized detection engines designed for high-accuracy DLP without false positives:
| Policy Type | Engine Description | Example Use Case |
|---|---|---|
| DLP_TEXT | High-speed regex and keyword pattern matching | Confidential project codenames API keys internal URLs |
| CHECKSUM | Mathematical checksum validation (Luhn & Modulus) | Credit Card numbers (Visa/Mastercard/Amex) and TCKN |
| DLP_FILE | File metadata extension and MIME type inspection | Blocking source code archives or database dumps |
| DLP_FILE_CONTENT | Deep document parsing and OCR (Turkish & English) | Extracting text from PDF DOCX and scanned image invoices |
| AI_PLATFORM | Deep DOM interception for 6 major GenAI services | Controlling prompts and blocking confidential code pastes into ChatGPT/Claude |
| NER | GLiNER deep learning Named Entity Recognition | Detecting person names customer identities and secret project mentions |
| THREAT_URL | Domain reputation and URL threat intelligence | Blocking known phishing malware and unauthorized command-and-control sites |
10Fleet Deployment & MDM Integration
Deploy Opsiton silently across thousands of enterprise workstations using your preferred endpoint management solution (Jamf, Kandji, Microsoft Intune, or Active Directory GPO).
macOS Enterprise MDM Deployment (.mobileconfig & PKG)
Deploy the native .pkg installer alongside MDM mobileconfig configuration profiles available directly in the Agent Deployment console to eliminate user prompts:
- system-extension.mobileconfig: Pre-authorizes Network Extension execution without end-user confirmation prompts
- content-filter.mobileconfig: Authorizes network content filter for data loss prevention inspection
- transparent-proxy.mobileconfig: Routes browser and desktop traffic safely through the local Opsiton Rust daemon
- pac-global-proxy.mobileconfig: Configures proxy auto-config (PAC) and enterprise direct domain bypass rules
macOS Silent CLI / Jamf Script
sudo installer -pkg OpsitonBrowsecure.pkg -target /
Windows Silent & Automated Deployment (MSI / Intune / GPO)
Install the Windows Agent silently with your fleet Enrollment Token:
msiexec /i OpsitonBrowsecure.msi ENROLLMENT_TOKEN="YOUR_ENROLLMENT_KEY" /qn
Browser Extension Force-Installation (Chrome & Edge)
Ensure the Chrome and Edge extensions are permanently installed and non-removable by pushing the ExtensionInstallForcelist policy via PowerShell or GPO:
$id = "opsiton-extension-id;https://clients2.google.com/service/update2/crx" New-Item -Path "HKLM:\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist" -Force | Out-Null Set-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist" -Name "1" -Value $id New-Item -Path "HKLM:\SOFTWARE\Policies\Microsoft\Edge\ExtensionInstallForcelist" -Force | Out-Null Set-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Edge\ExtensionInstallForcelist" -Name "1" -Value $id
11Inviting Team Members
To grant security team members access to the Tenant Portal:
- 1Navigate to Users in the sidebar
- 2Click the Invite User button
- 3Enter the corporate email address
- 4Select the appropriate role: Viewer, User, or Tenant Admin
- 5Click Send Invite
12Accepting an Invitation
- 1Open the automated invitation email received from Opsiton
- 2Click the secure invitation link
- 3Set a strong account password
- 4Sign in with your new credentials
- 5You will land directly on the Dashboard with your assigned permissions
13API Keys & Enrollment Tokens
Opsiton separates operational API keys from device enrollment credentials for defense-in-depth security:
Device Enrollment Tokens (ops_tok_...)
Used exclusively during endpoint agent installation to automatically register devices into your organization without exposing admin API privileges.
Organization API Keys (sk_opsiton_...)
Used for programmatic REST API access, CI/CD pipeline automation, and SIEM / SOAR integrations.
- 1Go to Settings > API Keys
- 2Click Create New Key
- 3Provide a descriptive label
- 4Copy and securely store the key immediately (it is only displayed once)
sk_opsiton_{org_slug}_{random_secret}14Endpoint Agent & Browser Extension Synergy
Opsiton delivers maximum endpoint visibility by combining an in-browser extension with a native background daemon:
Browser Extension (Chrome, Edge, Brave)
- Real-time DOM inspection: Evaluates text inside input fields, rich-text editors, and textareas before submission
- UI Protection: Renders user-friendly warn dialogs and block screens directly within the browser tab
- Native IPC: Communicates directly with the local agent daemon via loopback (127.0.0.1:44443) in under 1 millisecond
Native Endpoint Daemon (macOS & Windows)
- Transparent Proxy: Intercepts desktop apps (Slack, Teams, ChatGPT Desktop, IDEs) and CLI tools (curl, git)
- System Tray: Displays real-time protection health, policy sync status, and pause/maintenance controls
- Hardware Efficiency: Minimal resource footprint consuming less than 1% CPU and under 50MB RAM
15Security Events & Audit Logs
The Events page records every policy match across all enrolled endpoints in your organization.
| Audit Field | Description |
|---|---|
| Type | Detection category (DLP_TEXT, CHECKSUM, AI_PLATFORM, DLP_FILE, THREAT_URL, NER) |
| Rule Name | The exact policy rule that triggered the detection |
| Application / Domain | The web domain (e.g. chatgpt.com) or native process (e.g. curl.exe) involved |
| Severity | Critical, High, Medium, or Low severity ranking |
| Action Taken | Enforcement outcome: Blocked, Warned, Logged, or Masked |
| Masked Snippet | Sanitized excerpt of the matching text with sensitive digits redacted |
| Time | Precise UTC timestamp of the recorded event |
16Incident Triage & Response
Incidents represent high-priority security cases that require formal investigation, resolution, and compliance documentation.
| Lifecycle State | Definition |
|---|---|
| Open | Newly created incident awaiting triage and investigator assignment |
| Investigating | An assigned security analyst is actively analyzing root cause and risk |
| Resolved | Remediation actions taken, risk mitigated, and resolution notes recorded |
| Closed | Formally approved and archived case for audit compliance |
17Active Endpoints & Fleet Inventory
The Active Users page provides a live inventory of all registered endpoints across your enterprise.
| Inventory Field | Description |
|---|---|
| Hostname | Device hostname and network identity |
| Operating System | macOS (Apple Silicon / Intel) or Windows (10 / 11 / Server) |
| Status | Online (currently connected) or Offline |
| Agent Version | Installed version of the native Rust daemon |
| Extension Version | Installed version of the browser extension |
| Health & Protection | Real-time status: Protected, Warning, or Paused |
| Last Seen | Timestamp of the most recent heartbeat |
18Generative AI Platform Protection
Opsiton includes specialized, deep DOM adapters for six major enterprise GenAI platforms:
- Supported Platforms: OpenAI ChatGPT, Anthropic Claude, Google Gemini, Microsoft Copilot, DeepSeek, and Perplexity
- Prompt Interception: Inspects user prompts before transmission, blocking source code, customer records, or API credentials
- Paste Blocking: Detects clipboard pasting of large confidential codebases or confidential customer data
- File Upload Filtering: Pre-inspects documents attached to AI chat sessions and prevents proprietary document exposure
19Latency Telemetry & High Performance
Data security must not compromise employee productivity. Opsiton is engineered in Rust for ultra-low latency enforcement.
- Sub-15ms Proxy Overhead: P95 latency overhead introduced by the local proxy is under 15 milliseconds
- Transparent Telemetry: The /performance console displays live round-trip latency, upstream TTFB, and regex/OCR evaluation times
- Zero Impact on Browsing: Local pre-filtering bypasses non-inspected traffic immediately, ensuring full network speed
20Settings & SIEM / Webhook Integrations
Connect Opsiton into your existing enterprise security stack and alert workflows.
| Integration | Functionality |
|---|---|
| Slack Webhooks | Streams real-time notifications for High and Critical policy violations directly into SOC Slack channels |
| SIEM & Webhook Forwarding | Streams structured JSON event payloads to Microsoft Sentinel, Splunk, Datadog, or custom HTTPS endpoints |
| Session Security & 2FA | Enforce two-factor authentication and session timeouts for all portal administrators |
21Subscription Plans & Enforced Limits
Opsiton offers straightforward pricing with no artificial policy limits. All plans enjoy unlimited security policies.
| Plan | Portal Users | Application Users (Seats) | Key Features Included |
|---|---|---|---|
| Free | 2 Users | 1 Endpoint | Unlimited Policies, Preset DLP Templates, Incidents, NER & OCR |
| Starter | 3 Users | Billed per seat ($50/yr) | Unlimited Policies, Central Logging, Host Groups |
| Professional | 10 Users | Billed per seat ($100/yr) | File & MIME Rules, Incidents Workflow, Webhook Integrations |
| Business | 25 Users | Billed per seat ($150/yr) | GLiNER NER Models, Image OCR, Custom Rule Editor, Browser Extension & Agent |
| Enterprise | Unlimited | Custom Fleet (Billed per seat) | Masking/Redaction, Chrome CVE Scanning, On-Premise Deployment, Dedicated Support |
21-Day Free Business Trial
Every new organization starts with a full-featured 21-day trial of the Business plan covering up to 10 portal users and 40 endpoint agent seats. At the end of the trial, your account seamlessly transitions to the Free plan with no data loss.
22Security Posture Scoring Formula
The Security Score on your Dashboard represents the overall risk health of your fleet on a scale of 0 to 100.
- Incident Impact: Open, unresolved incidents apply a weighted reduction based on severity
- Event Volume: High and Critical severity violations within the last 7 days lower the overall score
- Triage Velocity: Promptly investigating and resolving incidents restores your score back toward 100%
- Fleet Hygiene: Outdated agent or browser versions introduce minor deductions until updated

