Security
The platform meets the standard it makes auditable.
A system for information security must be secure itself. This page describes the measures with which we separate data, control access and keep changes traceable.
Tenants and access
Multi-tenant isolation
Every organisation is separated server-side. Requests are checked against the tenant context - data never leaves the tenant boundary.
Role-based permissions (RBAC)
Permissions follow roles and are enforced server-side, not merely hidden in the interface.
Two-factor authentication
2FA is available and can be required across an organisation.
SSO and SCIM
Sign in through your identity provider; access is automatically provisioned and revoked via SCIM.
Data and operations
Encryption
Data is encrypted in transit and at rest.
Operated in the EU
Processing and data storage take place in the EU.
Security headers
Delivered with strict HTTP security headers against common attack classes.
Rate limiting
Public endpoints and forms are limited against automated load and abuse.
Traceability
Audit log
Security-relevant actions are logged and remain traceable.
Versioning and approvals
Documents and assessments carry their history - who approved what, and when.
Controlled evidence access
The trust center shares evidence in tiers and logs who accesses what.
This overview describes the product architecture and does not replace an audit certificate. Concrete evidence and data-processing agreements are provided as part of an enquiry.