For CTOs, CIOs & developers

Built for the people who have to run it

A low-code surface is only as good as what sits underneath it. Opzaro's process designer, AI and e-signature all run on real architecture: hardware-isolated code execution, a token-authenticated API, enterprise SSO, and a dedicated instance per customer — not a shared, multi-tenant backend you're trusting blind. See our guide on how to orchestrate systems and APIs without the integration sprawl.

Architecture & extensibility

API-first, and readable at every layer

Every action available in the UI is available via API. Processes are modelled visually on an embedded BPMN.io diagram editor — a real, portable BPMN definition, not a proprietary format — and step logic in PHP or Python has full access to the platform's own helper functions and, from within a script, to Opzaro's own API using the signed-in user's identity.

Portable BPMN definitions

Whole processes — diagram, forms and code — export and import as a single package for backup, version control or promotion between environments.

Reusable function libraries

Admins upload shared helper-function libraries available to every step's code, across every process — automation building blocks built once, reused everywhere.

Token-authenticated REST API

The e-signature module alone exposes a full x-api-token-authenticated API covering documents, templates, contacts, folders and webhooks.

Real languages, visible code

Step logic is written in PHP or Python — languages your team already knows — living visibly inside the workflow, not hidden in a black box.

Full GitHub integration

Processes, step code and permissions synchronise with a git repository — auditable source control, and clean support for dev, staging and production instances.

Secure code execution

Hardware-isolated sandboxing, not a scripting sandbox

When a step needs real custom logic beyond the visual tools, that code runs inside its own AWS Firecracker microVM — genuine hardware-level virtualization per execution. One tenant's custom step code cannot affect another's, or the host — a meaningful security differentiator for a low-code platform that lets customers run their own code.

A pre-baked base image lets each sandboxed job start in tens of milliseconds rather than seconds, via warm image snapshots. Both PHP and Python are supported, with Python code getting full access to the platform's own helper functions (AI calls, email, SharePoint, signing) through a secure bridge — without secrets ever leaving the trusted side. On simpler hosting where microVM sandboxing isn't set up, code still runs in-process, so the product scales down as well as up.

Step code triggersCustom PHP / Python logic
Firecracker microVMHardware-isolated, per execution
Warm snapshot poolCold start in tens of ms
Integrations

Orchestrate every system and API you already run

Microsoft Entra (Azure AD) SSO

Full enterprise SSO with tenant restriction and Azure AD group-based admin/permission mapping, refreshed automatically as group membership changes.

SharePoint & OneDrive

Native read/write of files and folders, and the ability to use SharePoint Lists as a lightweight database directly from workflow steps.

Inbound email as a trigger

A task can pause and wait for an email reply, matched automatically to the right waiting task by subject or body reference, then resume on arrival.

WhatsApp messaging

Steps can send WhatsApp messages and pause waiting for a reply from a specific number — customer- or field-worker-facing processes over a channel people already use.

Generic inbound webhooks

Any step can pause until a matching external system posts data back — the same mechanism e-signature completion uses, reusable for payment processors, CRMs or internal tools.

Identity verification (Didit KYC)

A step can kick off and wait on a full identity-verification session, with secure webhook confirmation — for onboarding, compliance and fintech-style processes.

Power Automate bridge

A step can hand its current data to an external automation endpoint (e.g. a Power Automate flow) and read updated values back.

Generic outbound API calls

Step logic can call any external REST API directly, or call Opzaro's own API using the signed-in user's identity.

Region-aware transactional email

EU/US region-aware transactional email sending for notifications, reminders and approvals.

Security & access control

Fine-grained by default, enterprise-ready when you need it

Users sign in passwordlessly with a single-use, time-limited magic link by default — no password-reset friction, one less credential for attackers to target — and fall back automatically to full Entra ID SSO when configured. Permissions can be granted at the whole-process level or narrowed to one specific step, to individual users or to groups, and team leads manage their team's tasks without full administrator rights.

A specific task step can be sent to someone outside the organisation as a single-use, time-limited link — no account, no password, works once, expires automatically. A signed-in user's identity can be securely handed off to an external tool (e.g. an embedded signing or verification service) without sharing credentials.

Passwordless by default, Entra SSO when you need it

Zero extra configuration to move from a small-team login model to enterprise identity.

Secrets masked, config centralised

Sign-in provider, integrations, and infrastructure settings are all managed from one admin screen, with secrets masked in the UI.

White-label branding

Application name, tagline, logo and full theme colour palette are configurable, so the platform can be presented under your own brand.

Deployment & data ownership

Your own instance, your own database, verifiably

A scripted installer provisions a complete production stack — web server, PHP, database, HTTPS certificates, and optional Firecracker sandboxing — as its own isolated deployment. Each customer gets a dedicated instance and database, with its own independent scheduler, config and database, not a shared multi-tenant backend.

Every deployment is automatically recorded — server, domain, exact code commit, and timestamp — and the running application's footer links directly to the exact commit currently live in production, so you can verify precisely what's running and when it was deployed.

footer → exact commit + deploy timestamp, always visible
Your instance
Web server + PHPDedicated, isolated
DatabaseYour data only
SchedulerIndependent cron, per customer
Another customer's instance
Web server + PHPDedicated, isolated
DatabaseTheir data only
SchedulerIndependent cron, per customer
Common questions

Orchestrating systems and APIs: common questions

1

What does it mean to orchestrate systems and APIs in one platform?

A single workflow engine coordinates the handoffs between your existing systems — SSO, document stores, messaging channels, payment processors, internal tools — rather than each integration living as a one-off script. Every UI action is available via API, so orchestration is part of the process definition itself.

2

Can I connect my own APIs and existing systems to a workflow?

Yes. Step logic can call any external REST API directly, or call Opzaro's own API using the signed-in user's identity. Generic inbound webhooks let any step pause until a matching external system posts data back.

3

Is API orchestration secure if I'm running custom code?

Custom step code runs inside its own Firecracker microVM — hardware-level virtualization per execution — so one tenant's code cannot affect another's or the host, with secrets never leaving the trusted side of the bridge.

4

Do I need to replace my existing systems to orchestrate them?

No. Opzaro sits inside your existing technology landscape — Azure AD/Entra, SharePoint, email, WhatsApp, identity verification, Power Automate — and orchestrates across them rather than replacing any of them.

Bring your architecture questions — we'll answer them directly

SSO, sandboxing, API surface, deployment isolation — ask us anything you'd ask before signing off on a platform.