HomeDocumentation

Opsiton Platform User Guide

Comprehensive guide for end users and tenant admins. Learn how to deploy, configure, and operate the Opsiton dual-layer DLP platform.

Last updated: October 1, 2026

1What is Opsiton?

Opsiton is a modern, dual-layer endpoint Data Loss Prevention (DLP) platform. It prevents confidential and regulated data from leaving corporate devices — across web browsers, desktop applications, developer IDEs, and command-line terminal tools.

Dual-Layer Architecture

  1. 1Central Management: Administrators define and publish security policies from the Tenant Portal
  2. 2Native Endpoint Agent: A lightweight Rust daemon (with WFP driver on Windows or Network Extension on macOS) intercepts system traffic and terminal commands
  3. 3Browser Extension: Deep DOM and UI interception inside Chrome, Edge, and Brave for instant user warnings and block screens
  4. 4Local Transparent Proxy: Enforces real-time DLP inspection at 127.0.0.1:44443 with sub-15ms latency
  5. 5Real-time Visibility: Sanitized security events and incidents sync to the Opsiton portal for audit and investigation

What Opsiton Detects

  • Sensitive text typed into web forms and chat inputs
  • Credit card numbers validated via Luhn checksum algorithm
  • TCKN and Turkish IBAN validated with algorithmic modulus checks
  • File uploads inspected by MIME type, extension, and full text extraction (PDF, DOCX)
  • Turkish and English OCR extraction from uploaded image files
  • Data pasted into GenAI platforms (ChatGPT, Claude, Gemini, Copilot, DeepSeek, Perplexity)
  • Visits to malicious, phishing, or unapproved threat URLs
  • Terminal commands and desktop application network exfiltration

2Platform Components

ComponentTarget SurfacePurpose
Tenant PortalAdmins & Security TeamsCentral web console (bs-portal.opsiton.com) to manage policies events incidents users and deployment
Native Endpoint AgentmacOS & Windows DevicesHigh-performance Rust core that runs transparent proxy inspection and enforces policies locally
Browser ExtensionChrome Edge Brave ChromiumIntercepts paste drag-and-drop form submissions and delivers in-browser warn/block dialogs
Local Transparent ProxyLocal Loopback (127.0.0.1:44443)System-wide inspection gate for desktop apps IDEs and terminal utilities outside the browser
Super Admin & TelemetryPlatform OperatorsCentral health telemetry (bs-admin.opsiton.com) monitoring agent fleet latency and performance

3Privacy & Zero-Data-Exfiltration Architecture

Opsiton is architected on a strict Zero-Data-Exfiltration model. Your sensitive files, confidential prompts, and private customer records never leave the local endpoint to Opsiton cloud servers.

  • On-Device Inspection: All regex matching, Luhn checksums, OCR parsing, and GLiNER NER model evaluations execute 100% locally on the device CPU/GPU
  • Sanitized Event Telemetry: When a policy violation occurs, Opsiton transmits only sanitized metadata: rule name, timestamp, domain/application name, severity, and a SHA-256 content hash with masked snippet
  • Zero Plaintext Storage: Neither the portal nor Opsiton cloud databases ever receive or store the raw sensitive data.
Compliance Guarantee: This architecture ensures full compliance with KVKK, GDPR, and PCI-DSS, eliminating third-party cloud data residency concerns.

4Fail-Safe Architecture: Fail-Open vs. Fail-Closed (REQ-PRX-001)

An IT buyer's primary reliability question is: "What happens if your agent crashes or the daemon stops?" Opsiton operates under a formal fail-safe contract (REQ-PRX-001) that transparently balances non-disruptive business operations against zero data compromise.

Target vs. General Traffic Contract

Traffic CategoryAgent HealthyAgent Stopped / DegradedRationale & Enforcement
Admin-Targeted Risk Domains (ChatGPT Claude Gemini etc.)Transparent MITM Inspection & Policy EnforcementFail-Closed (Immediate Connection Drop)Prevents confidential data leakage when inspection engine is unavailable
General Business Traffic & Non-Risk WebsitesInspected or Direct RoutingFail-Open (Direct Connection)Prevents enterprise network outages; an unhealthy agent is an IT ticket not a company blackout
Direct Exemption Domains & OS InfrastructureDirect Bypass RouteFail-Open (Direct Connection)Preserves OS updates Apple APNs MDM commands and enterprise internal systems

Enterprise Norm & Empirical Verification

  • Industry Standard: Leading enterprise DLP and network security products (Forcepoint "no policies are enforced", GlobalProtect default fail-open) establish that endpoint security must not turn into a single point of operational network failure.
  • Empirical Live Verification: Validated on live Chrome and Safari sessions — when the Opsiton daemon is stopped, admin-monitored AI endpoints (chatgpt.com) are instantly dropped (fail-closed) while corporate web tools remain accessible (fail-open).
  • Automated IT Visibility: When an agent stops or loses policy synchronization, it reports a degraded status to the central portal and triggers IT diagnostics without disrupting end-user workflows.
Design Principle (REQ-PRX-001): "An unhealthy agent is an IT operational event, not a business outage." Critical AI vectors remain strictly protected while corporate business operations proceed uninterrupted.

5User Roles & Access Control

Access to the Tenant Portal is governed by role-based access control (RBAC):

RolePermissions
ViewerRead-only access to security events incidents active users policies and reports
UserStandard employee access with view permissions and self-service status checks
Tenant AdminFull administrative authority: create/edit policies invite members manage API keys deploy agents and manage subscriptions
Note: Policy creation, agent deployment token generation, and membership changes are restricted to Tenant Admins.

6Tenant Onboarding & Quick Start

Step 1: Register Your Organization

Visit the Tenant Portal (bs-portal.opsiton.com) and click Get Started or Register. Enter your full name, organization name, corporate work email, and secure password.

Step 2: Onboarding Setup

  1. 1Create your first DLP policy from verified compliance templates (e.g. Credit Card Luhn, TCKN, AI Platform)
  2. 2Obtain your fleet Enrollment Token from the Agent Deployment page
  3. 3Deploy the Opsiton Agent via MSI/PKG or MDM profiles with Chrome/Edge extension force-installation
  4. 4Verify live connection on the Dashboard

7Security Operations Dashboard

The Dashboard provides real-time situational awareness across your entire organization.

Security Posture Score

A dynamic 0-100 score quantifying fleet security health. The score decreases with unaddressed high-severity events and open incidents, and recovers as incidents are investigated and resolved.

Live KPI Cards

CardMetrics Shown
Portal UsersActive security team members with portal access
Application UsersTotal enrolled endpoint devices and real-time online count
Active PoliciesNumber of enabled DLP, AI, and Threat URL rules
Events 24hTotal security detections recorded over the last 24 hours
Open IncidentsUnresolved security cases requiring triage and investigation

8Policy Management & Enforcement

Policies dictate what data patterns to detect and what enforcement action to take when an employee interacts with sensitive data.

Enforcement Actions

ActionUser Experience & System Behavior
BlockImmediately terminates the transfer. Displays an instant full-screen or toast block dialog with the violation justification.
WarnDisplays an interactive warning dialog showing risk details. The user must provide a business justification to proceed or cancel the action.
LogSilently allows the action while recording an audit event in the portal for security analysis.
MaskAutomatically redacts sensitive tokens (e.g. masking credit card or identity numbers with asterisks) before transmission.

Built-in Rule Templates

  • Payment Cards (Luhn Algorithm checksum verification)
  • TC Kimlik No (11-digit modulus verification)
  • Türkiye IBAN (ISO 7064 MOD 97-10 checksum)
  • Turkish Mobile & Landline Phone Numbers
  • Email Addresses & Confidential Token Patterns
  • GDPR, KVKK, and PCI-DSS Compliance Frameworks

9Policy Types & Detection Engines

Opsiton features six specialized detection engines designed for high-accuracy DLP without false positives:

Policy TypeEngine DescriptionExample Use Case
DLP_TEXTHigh-speed regex and keyword pattern matchingConfidential project codenames API keys internal URLs
CHECKSUMMathematical checksum validation (Luhn & Modulus)Credit Card numbers (Visa/Mastercard/Amex) and TCKN
DLP_FILEFile metadata extension and MIME type inspectionBlocking source code archives or database dumps
DLP_FILE_CONTENTDeep document parsing and OCR (Turkish & English)Extracting text from PDF DOCX and scanned image invoices
AI_PLATFORMDeep DOM interception for 6 major GenAI servicesControlling prompts and blocking confidential code pastes into ChatGPT/Claude
NERGLiNER deep learning Named Entity RecognitionDetecting person names customer identities and secret project mentions
THREAT_URLDomain reputation and URL threat intelligenceBlocking known phishing malware and unauthorized command-and-control sites

10Fleet Deployment & MDM Integration

Deploy Opsiton silently across thousands of enterprise workstations using your preferred endpoint management solution (Jamf, Kandji, Microsoft Intune, or Active Directory GPO).

macOS Enterprise MDM Deployment (.mobileconfig & PKG)

Deploy the native .pkg installer alongside MDM mobileconfig configuration profiles available directly in the Agent Deployment console to eliminate user prompts:

  • system-extension.mobileconfig: Pre-authorizes Network Extension execution without end-user confirmation prompts
  • content-filter.mobileconfig: Authorizes network content filter for data loss prevention inspection
  • transparent-proxy.mobileconfig: Routes browser and desktop traffic safely through the local Opsiton Rust daemon
  • pac-global-proxy.mobileconfig: Configures proxy auto-config (PAC) and enterprise direct domain bypass rules

macOS Silent CLI / Jamf Script

sudo installer -pkg OpsitonBrowsecure.pkg -target /

Windows Silent & Automated Deployment (MSI / Intune / GPO)

Install the Windows Agent silently with your fleet Enrollment Token:

msiexec /i OpsitonBrowsecure.msi ENROLLMENT_TOKEN="YOUR_ENROLLMENT_KEY" /qn

Browser Extension Force-Installation (Chrome & Edge)

Ensure the Chrome and Edge extensions are permanently installed and non-removable by pushing the ExtensionInstallForcelist policy via PowerShell or GPO:

$id = "opsiton-extension-id;https://clients2.google.com/service/update2/crx"
New-Item -Path "HKLM:\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist" -Force | Out-Null
Set-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist" -Name "1" -Value $id
New-Item -Path "HKLM:\SOFTWARE\Policies\Microsoft\Edge\ExtensionInstallForcelist" -Force | Out-Null
Set-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Edge\ExtensionInstallForcelist" -Name "1" -Value $id

11Inviting Team Members

To grant security team members access to the Tenant Portal:

  1. 1Navigate to Users in the sidebar
  2. 2Click the Invite User button
  3. 3Enter the corporate email address
  4. 4Select the appropriate role: Viewer, User, or Tenant Admin
  5. 5Click Send Invite
Team member seat limits depend on your active subscription plan. Admins can revoke or resend invites at any time.

12Accepting an Invitation

  1. 1Open the automated invitation email received from Opsiton
  2. 2Click the secure invitation link
  3. 3Set a strong account password
  4. 4Sign in with your new credentials
  5. 5You will land directly on the Dashboard with your assigned permissions

13API Keys & Enrollment Tokens

Opsiton separates operational API keys from device enrollment credentials for defense-in-depth security:

Device Enrollment Tokens (ops_tok_...)

Used exclusively during endpoint agent installation to automatically register devices into your organization without exposing admin API privileges.

Organization API Keys (sk_opsiton_...)

Used for programmatic REST API access, CI/CD pipeline automation, and SIEM / SOAR integrations.

  1. 1Go to Settings > API Keys
  2. 2Click Create New Key
  3. 3Provide a descriptive label
  4. 4Copy and securely store the key immediately (it is only displayed once)
sk_opsiton_{org_slug}_{random_secret}

14Endpoint Agent & Browser Extension Synergy

Opsiton delivers maximum endpoint visibility by combining an in-browser extension with a native background daemon:

Browser Extension (Chrome, Edge, Brave)

  • Real-time DOM inspection: Evaluates text inside input fields, rich-text editors, and textareas before submission
  • UI Protection: Renders user-friendly warn dialogs and block screens directly within the browser tab
  • Native IPC: Communicates directly with the local agent daemon via loopback (127.0.0.1:44443) in under 1 millisecond

Native Endpoint Daemon (macOS & Windows)

  • Transparent Proxy: Intercepts desktop apps (Slack, Teams, ChatGPT Desktop, IDEs) and CLI tools (curl, git)
  • System Tray: Displays real-time protection health, policy sync status, and pause/maintenance controls
  • Hardware Efficiency: Minimal resource footprint consuming less than 1% CPU and under 50MB RAM

15Security Events & Audit Logs

The Events page records every policy match across all enrolled endpoints in your organization.

Audit FieldDescription
TypeDetection category (DLP_TEXT, CHECKSUM, AI_PLATFORM, DLP_FILE, THREAT_URL, NER)
Rule NameThe exact policy rule that triggered the detection
Application / DomainThe web domain (e.g. chatgpt.com) or native process (e.g. curl.exe) involved
SeverityCritical, High, Medium, or Low severity ranking
Action TakenEnforcement outcome: Blocked, Warned, Logged, or Masked
Masked SnippetSanitized excerpt of the matching text with sensitive digits redacted
TimePrecise UTC timestamp of the recorded event

16Incident Triage & Response

Incidents represent high-priority security cases that require formal investigation, resolution, and compliance documentation.

Lifecycle StateDefinition
OpenNewly created incident awaiting triage and investigator assignment
InvestigatingAn assigned security analyst is actively analyzing root cause and risk
ResolvedRemediation actions taken, risk mitigated, and resolution notes recorded
ClosedFormally approved and archived case for audit compliance
Admins can escalate any single security event into a formal incident or configure automated incident creation for repeated high-severity violations.

17Active Endpoints & Fleet Inventory

The Active Users page provides a live inventory of all registered endpoints across your enterprise.

Inventory FieldDescription
HostnameDevice hostname and network identity
Operating SystemmacOS (Apple Silicon / Intel) or Windows (10 / 11 / Server)
StatusOnline (currently connected) or Offline
Agent VersionInstalled version of the native Rust daemon
Extension VersionInstalled version of the browser extension
Health & ProtectionReal-time status: Protected, Warning, or Paused
Last SeenTimestamp of the most recent heartbeat

18Generative AI Platform Protection

Opsiton includes specialized, deep DOM adapters for six major enterprise GenAI platforms:

  • Supported Platforms: OpenAI ChatGPT, Anthropic Claude, Google Gemini, Microsoft Copilot, DeepSeek, and Perplexity
  • Prompt Interception: Inspects user prompts before transmission, blocking source code, customer records, or API credentials
  • Paste Blocking: Detects clipboard pasting of large confidential codebases or confidential customer data
  • File Upload Filtering: Pre-inspects documents attached to AI chat sessions and prevents proprietary document exposure

19Latency Telemetry & High Performance

Data security must not compromise employee productivity. Opsiton is engineered in Rust for ultra-low latency enforcement.

  • Sub-15ms Proxy Overhead: P95 latency overhead introduced by the local proxy is under 15 milliseconds
  • Transparent Telemetry: The /performance console displays live round-trip latency, upstream TTFB, and regex/OCR evaluation times
  • Zero Impact on Browsing: Local pre-filtering bypasses non-inspected traffic immediately, ensuring full network speed

20Settings & SIEM / Webhook Integrations

Connect Opsiton into your existing enterprise security stack and alert workflows.

IntegrationFunctionality
Slack WebhooksStreams real-time notifications for High and Critical policy violations directly into SOC Slack channels
SIEM & Webhook ForwardingStreams structured JSON event payloads to Microsoft Sentinel, Splunk, Datadog, or custom HTTPS endpoints
Session Security & 2FAEnforce two-factor authentication and session timeouts for all portal administrators

21Subscription Plans & Enforced Limits

Opsiton offers straightforward pricing with no artificial policy limits. All plans enjoy unlimited security policies.

PlanPortal UsersApplication Users (Seats)Key Features Included
Free2 Users1 EndpointUnlimited Policies, Preset DLP Templates, Incidents, NER & OCR
Starter3 UsersBilled per seat ($50/yr)Unlimited Policies, Central Logging, Host Groups
Professional10 UsersBilled per seat ($100/yr)File & MIME Rules, Incidents Workflow, Webhook Integrations
Business25 UsersBilled per seat ($150/yr)GLiNER NER Models, Image OCR, Custom Rule Editor, Browser Extension & Agent
EnterpriseUnlimitedCustom Fleet (Billed per seat)Masking/Redaction, Chrome CVE Scanning, On-Premise Deployment, Dedicated Support

21-Day Free Business Trial

Every new organization starts with a full-featured 21-day trial of the Business plan covering up to 10 portal users and 40 endpoint agent seats. At the end of the trial, your account seamlessly transitions to the Free plan with no data loss.

22Security Posture Scoring Formula

The Security Score on your Dashboard represents the overall risk health of your fleet on a scale of 0 to 100.

  • Incident Impact: Open, unresolved incidents apply a weighted reduction based on severity
  • Event Volume: High and Critical severity violations within the last 7 days lower the overall score
  • Triage Velocity: Promptly investigating and resolving incidents restores your score back toward 100%
  • Fleet Hygiene: Outdated agent or browser versions introduce minor deductions until updated
The score continuously recalculates every 15 minutes based on a sliding 7-day event window and 30-day incident resolution history.