Security & trust

Trust isn't a feature. It's the audit trail.

Row-level security on every table. A tamper-evident audit log on every action. Tokenised external sharing for auditors, insurers and contractors.

How your data is protected

Security built into the database, not bolted on.

Row-level security on every table

Row-level security policies are enforced server-side across all 92 database tables — every table, zero lockouts. Your organisation's data cannot be reached by another tenant, even by a misconfigured client.

Tamper-evident audit log

An append-only audit_log table records system events. Entries are written, never edited or deleted — the evidence chain auditors, regulators and insurers expect.

Multi-tenant isolation

Every read and write is scoped by organisation. RLS plus server-side middleware guarantees that one workspace can never see, list or modify another's records.

Leaked-password protection

New and changed passwords are checked against known-breached credentials. Compromised passwords are rejected before they ever protect an account.

Verified email & authenticated sessions

Email verification on signup, secure session cookies and Google OAuth. Microsoft SSO is wired and ready to enable when needed.

Role-based access control

Owner, Admin, Manager, Viewer and Contractor roles — each scoped to exactly what they should see. Contractors are further restricted by RLS to their own assigned assets.

Sharing & hosting

Controlled access. Cloud-hosted. No install.

Tokenised external sharing

Audit packs and contractor work links use cryptographically random, time-limited tokens. Auditors, insurers and contractors get exactly what they need — nothing more.

Expiry & revocation

Every shared link has an explicit expiry date. Tokens can be revoked instantly. Expired or revoked links show a clear error rather than leaking content.

Cloud-hosted, no install

Hosted on enterprise-grade cloud infrastructure. Accessible from any browser and installable as a Progressive Web App on Android and iOS. No hardware, no agents, no on-prem maintenance.

Continuous hardening

Security is a moving target. So are we.

A sample of recent targeted improvements — part of ongoing work to keep the platform aligned with the threat landscape.

Contractor work links

Plaintext token reading is restricted to Owners and Admins only. Managers retain create/update/delete permissions but can no longer read secret tokens.

Installed template packs

A membership check on the read policy means a tampered active-organisation setting cannot expose another organisation's installed packs.

Task attachments

A redundant duplicate read policy was removed — eliminating an unnecessary code path to attachment data.

Ready when you are

See the audit trail in action.

Start a free trial and explore the activity log, role-based access and tokenised audit pack sharing for yourself. No credit card required.