Security

Security, safeguards and standards, in place from day one.

Permissions set per person, per entity.

01 — Access

Permissions, not roles.

Each area has its own four flags, and the system checks them on every request — not just the menu.

Four flags per areaRead, create, update and delete on clients, projects, tasks, users, invoices and the organization. Set per person, changed any time.
Owners and admins see everythingThe two roles that run an organization are never locked out. Only the owner can hand ownership to someone else.
Nobody edits their ownA user cannot change their own permissions, whatever their role; the system refuses it. Someone else has to, and the change is logged under their name.
02 — Isolation

Your data is yours. Nobody else can see it.

  • Kept apart. Your organization's records are separated from everyone else's in the database itself, not just on the screen.
  • Only your people. Someone in your organization has to add a person before they can sign in. There is nothing to browse or request.
  • Yours to take. It is your data. Ask and we will hand over a copy, or delete it.
03 — Safeguards

Who sees what. Decided per person.

  • Rate limits on every endpointEvery request to the api is rate limited, sign-in most strictly. Signing out ends the session.
  • Encrypted connectionsAll traffic is served over HTTPS. Card details never reach our servers.
  • Continuous monitoringErrors are reported automatically and reviewed as they occur.