How we protect your data
Role-based access control starts closed. A role grants only the permissions it is explicitly given, and platform administration is separated from tenant roles entirely.
Every record is scoped to its tenant. One organisation can never read or write another’s data — enforced in the data layer, not just the UI.
Security-relevant actions are written to an immutable audit log with actor, subject, before/after and source — the evidence a real investigation needs.
Data is encrypted in transit (TLS) and at rest. Secrets are held in configuration, never in the codebase.
Enterprise HTTP security headers are applied to every response by default, closing common browser-side attack classes.
A Security Intelligence layer assesses the platform against a control catalogue and surfaces findings — security is measured, not assumed.
Controls at a glance
What is live today, and what is on the way. We report status honestly.
Need our security documentation?
We share our architecture overview and answer security questionnaires under NDA.