Security is not an enterprise feature
Small businesses hold the same sensitive information as large ones โ contracts, payment details, personal data โ usually with less protection. Everything here applies on every plan.
Encryption everywhere
Data is encrypted in transit with TLS and at rest in storage. Personal data is held separately from operational records, so it can be removed without disturbing the rest of your history.
Tamper-evident history
Document and record history is hash-chained โ each entry commits to the one before it, so any alteration is detectable. Verification is available to you, not just to us.
Access control that matches your org
Role-based permissions across every module, with multi-factor authentication and passkey support. The AI assistant respects the same permissions โ it cannot surface a record the person asking isn't allowed to see.
Bounded automation
Every workflow runs inside a spending ceiling and an explicit permission boundary enforced by the platform. An automation cannot reach records outside its lane, regardless of how it is prompted.
Backups and recovery
Automated daily backups with point-in-time recovery. Backups are encrypted and tested โ an untested backup is not a backup.
Your data, exportable
Full export of records, documents and audit history in standard formats, any time, without contacting support. Portability is a feature, not a concession.
What we don't claim
Vendors routinely imply certifications they don't hold. We'd rather be direct: where a formal certification or attestation is relevant to your industry, ask us and we'll tell you exactly what we hold today and what is in progress. If a requirement is one we can't meet, we will say so before you sign rather than after you discover it.