Tenant isolation
Each company is isolated at the database layer.
Tenant isolation is enforced at the database layer. Access follows role-based permissions, with MFA available. Activity and audit logging, nightly backups and UK-hosted data complete the operating baseline.
Six controls, plainly stated
Each company is isolated at the database layer.
Access follows the role permissions in place.
Multi-factor authentication is available.
Activity and audit logging are built in.
Backups run nightly.
Data is hosted in the UK.
In more detail
Plain descriptions of the controls above, including the limits of what is claimed.
Separation between companies is enforced where the records are stored, not only in the interface. That is a deliberate choice: an interface-level check can be bypassed by a bug in one screen, whereas a company boundary held at the data layer applies to every query.
Access follows role-based permissions across the web platform and the mobile app, so people see the work their role covers. Multi-factor authentication is available for accounts that need a second factor.
Activity and audit logging are built in, so account and record activity can be reviewed after the fact. Backups run nightly, and data is hosted in the UK.
Every control above is running in the product today, and the list stops where the product stops. There are no external security marks on this page, and there will not be any until they are real. If you need assurance beyond what is here, ask directly on a demo and you will get a straight answer.
Ask the direct questions