Skip to content
Compliflux

Security

The platform meets the standard it makes auditable.

A system for information security must be secure itself. This page describes the measures with which we separate data, control access and keep changes traceable.

Tenants and access

Multi-tenant isolation

Every organisation is separated server-side. Requests are checked against the tenant context - data never leaves the tenant boundary.

Role-based permissions (RBAC)

Permissions follow roles and are enforced server-side, not merely hidden in the interface.

Two-factor authentication

2FA is available and can be required across an organisation.

SSO and SCIM

Sign in through your identity provider; access is automatically provisioned and revoked via SCIM.

Data and operations

Encryption

Data is encrypted in transit and at rest.

Operated in the EU

Processing and data storage take place in the EU.

Security headers

Delivered with strict HTTP security headers against common attack classes.

Rate limiting

Public endpoints and forms are limited against automated load and abuse.

Traceability

Audit log

Security-relevant actions are logged and remain traceable.

Versioning and approvals

Documents and assessments carry their history - who approved what, and when.

Controlled evidence access

The trust center shares evidence in tiers and logs who accesses what.

This overview describes the product architecture and does not replace an audit certificate. Concrete evidence and data-processing agreements are provided as part of an enquiry.