Security
Last updated 20 August 2026
This product holds the exact set of details an identity thief would want, for people who are already targeted by immigration scams. We treat that as the main engineering problem, not an afterthought.
Your most sensitive details are encrypted
Your SEVIS ID, EAD number, A-Number, passport number, I-94 number, date of birth, home address and signature image are encrypted by the application before they reach the database, using AES-256-GCM. The key lives separately from the database, so database access on its own reveals nothing.
They never leak out sideways
- Never in a web address, so they cannot end up in server logs or browser history.
- Never in application logs or crash reports — a redaction layer strips them first.
- Never in analytics.
- Never in an email. When you email yourself a copy of a document, we send a secure link that expires, not an attachment.
- Never in a prompt to an AI model — with one exception you choose yourself, below.
If you upload your I-20 or EAD card
You can upload your I-20 or your EAD card — the PDF you already have, or a photo — and we will read it, so you do not have to type your SEVIS ID or EAD number by hand. That is the one time an identifier of yours reaches an AI model, so it is worth being clear about what happens: the file is sent to our AI provider to be read, we do not store it anywhere, it never appears in a log or a crash report, and nothing it says goes onto your form until you have checked each value and chosen to use it. If you upload a PDF we turn its first page into a picture in memory to read it; no copy of it is written down anywhere. We read what is printed — we do not tell you whether a document is correct, and we cannot. Your DSO does that.
It is optional and it stays optional. Typing every field yourself is a normal way to use OPTPrep, not a fallback, and nothing is held back from you for choosing it.
Shared and library computers
We assume you might be on one. Sensitive fields are never written to browser storage, sessions time out, and there is a “this is a shared computer” option at sign-in that ends your session when you close the tab. Once saved, identifiers display masked, with a button to reveal them.
Only you can see your documents
Access is enforced in the database itself, not just in the application, so a bug in one layer does not expose another person’s file. When you share a link with your employer, it is scoped to the sections you chose, it expires, and you can revoke it. It never exposes your SEVIS ID or passport number.
Reporting a vulnerability
Email security@optprep.com. We will acknowledge within 72 hours. Good-faith research is welcome — please test against your own account rather than someone else’s data.