Back to WorkspaceSecurity Policy

Security Policy

Platform Security Controls

Last updated: 2026-05-20

Access Restrictions

Access to protected API resources requires authenticated sessions. Administrative endpoints are restricted to assigned admin and super-admin roles.

Database row-level security policies are enabled for operational tables and supporting compliance tables.

Encryption

Transport security is enforced through HTTPS/TLS for application and third-party API communication.

Data-at-rest encryption is provided through managed infrastructure provider controls.

Audit Logging

Security-relevant and administrative operations are captured in an immutable audit log stream for operational review and incident investigation.

Role-Based Access

Access is controlled through role assignments for employee, admin, and super-admin users. Role checks are enforced at API boundaries before privileged actions are processed.

This includes restricting access to compliance summaries, administrative actions, and protected user data to authorized roles only.

Employee NDA and Device Policies

Employees acknowledge NDA and device policy requirements through in-app controls. Acknowledgement status is tracked and reported to administrators through compliance summaries.