Security Policy
Platform Security Controls
Last updated: 2026-05-20
Access Restrictions
Access to protected API resources requires authenticated sessions. Administrative endpoints are restricted to assigned admin and super-admin roles.
Database row-level security policies are enabled for operational tables and supporting compliance tables.
Encryption
Transport security is enforced through HTTPS/TLS for application and third-party API communication.
Data-at-rest encryption is provided through managed infrastructure provider controls.
Audit Logging
Security-relevant and administrative operations are captured in an immutable audit log stream for operational review and incident investigation.
Role-Based Access
Access is controlled through role assignments for employee, admin, and super-admin users. Role checks are enforced at API boundaries before privileged actions are processed.
This includes restricting access to compliance summaries, administrative actions, and protected user data to authorized roles only.
Employee NDA and Device Policies
Employees acknowledge NDA and device policy requirements through in-app controls. Acknowledgement status is tracked and reported to administrators through compliance summaries.