Trust isn't a feature. It's the audit trail.
Row-level security on every table. A tamper-evident audit log on every action. Tokenised external sharing for auditors, insurers and contractors.
Security built into the database, not bolted on.
Row-level security on every table
Row-level security policies are enforced server-side across all 92 database tables — every table, zero lockouts. Your organisation's data cannot be reached by another tenant, even by a misconfigured client.
Tamper-evident audit log
An append-only audit_log table records system events. Entries are written, never edited or deleted — the evidence chain auditors, regulators and insurers expect.
Multi-tenant isolation
Every read and write is scoped by organisation. RLS plus server-side middleware guarantees that one workspace can never see, list or modify another's records.
Leaked-password protection
New and changed passwords are checked against known-breached credentials. Compromised passwords are rejected before they ever protect an account.
Verified email & authenticated sessions
Email verification on signup, secure session cookies and Google OAuth. Microsoft SSO is wired and ready to enable when needed.
Role-based access control
Owner, Admin, Manager, Viewer and Contractor roles — each scoped to exactly what they should see. Contractors are further restricted by RLS to their own assigned assets.
Controlled access. Cloud-hosted. No install.
Tokenised external sharing
Audit packs and contractor work links use cryptographically random, time-limited tokens. Auditors, insurers and contractors get exactly what they need — nothing more.
Expiry & revocation
Every shared link has an explicit expiry date. Tokens can be revoked instantly. Expired or revoked links show a clear error rather than leaking content.
Cloud-hosted, no install
Hosted on enterprise-grade cloud infrastructure. Accessible from any browser and installable as a Progressive Web App on Android and iOS. No hardware, no agents, no on-prem maintenance.
Security is a moving target. So are we.
A sample of recent targeted improvements — part of ongoing work to keep the platform aligned with the threat landscape.
Contractor work links
Plaintext token reading is restricted to Owners and Admins only. Managers retain create/update/delete permissions but can no longer read secret tokens.
Installed template packs
A membership check on the read policy means a tampered active-organisation setting cannot expose another organisation's installed packs.
Task attachments
A redundant duplicate read policy was removed — eliminating an unnecessary code path to attachment data.
See the audit trail in action.
Start a free trial and explore the activity log, role-based access and tokenised audit pack sharing for yourself. No credit card required.

