Role-based permissions
Rights granted by role, company, document type and field, reviewed with you at go-live.
See how the modules share one ledger, one customer record and one set of controls.
Explore the platformTell us how you work today and we will map the shortest route to a connected system.
Book a demoA structured path from discovery to go-live, with training and support built in.
See the approachPlatform security
This page describes controls that are implemented and that you can inspect in your own tenant. Where something is not in place, we say so rather than implying it.
We make no claim to ISO 27001, SOC 2 or GDPR certification, and we publish no uptime guarantee, data-residency promise or encryption standard on this page. If your procurement process requires evidence on any of these, ask us directly and we will give you an accurate current answer.
Controls
Rights granted by role, company, document type and field, reviewed with you at go-live.
Submitted documents keep version history, timestamps and the user behind each change.
Documents can require approval by value, type or condition before they post.
Scheduled backups with documented restoration procedures.
Traffic between browsers and the platform runs over encrypted connections.
Each customer runs on its own instance and subdomain, with separate data.
Login and activity logs available to tenant administrators.
Session timeouts, password rules and access restrictions set per tenant.
Responsibility
Most security incidents in business systems involve access, not infrastructure. These are the controls your team owns.
Adding, changing and promptly removing user accounts when people join or leave.
Deciding who may approve, post, export and configure, and reviewing it periodically.
Keeping the person who raises a payment separate from the person who approves it.
Next step
Discuss your processes, reporting requirements and growth plans with our ERP specialists.