Security & Trust
Security built into the platform.
Isolation is a property of the database, not a setting on a page. This page describes each control, the privacy posture and the data flows from your browser.
- Database-level tenant isolation
- Per-app frame policy
- Explicit permission prompts
- Audit log for the actions auditors ask about
- Privacy rules per jurisdiction pack
- Health checks published
The controls
What is enforced, and where
Five controls built into the system.
Tenant isolation at the database layer
Every record carries your organization's identity, and the database itself refuses to return another organization's rows - even if application code asked it to.
A security policy for every app
Each app runs in its own frame under a policy built from what that app declared it needs. An app cannot quietly load scripts or send data to services it never declared.
Permission prompts you can see
Sensitive capabilities are requested explicitly - what is being asked for, and by which app - and can be refused.
Every action recorded
The Audit Log keeps who changed what, when and from where, for the actions your auditor asks about.
Privacy by jurisdiction
Each jurisdiction pack carries its privacy rules. The Hong Kong pack is specified against PDPO and the PCPD's codes of practice for HR data: collect what the purpose needs, keep it for the period the law requires, and support access and correction.
Data flows
What the public site sends, and when
The marketing site runs no advertising trackers. Three flows start in your browser, all first-party; each is listed with the condition that allows it.
| What leaves the browser | What it carries | When it is sent |
|---|---|---|
| Usage analytics | Named events with allow-listed properties only - page and action names, locale. Free text and sensitive keys are rejected before an event leaves the page. | Only with your analytics consent |
| Performance vitals | LCP, INP and CLS measurements from the browser's own performance observer, so load experience is measured where it actually happens. | Only with your analytics consent |
| Error reports | Uncaught errors and unhandled rejections on public pages - the route and the error, so a broken page is repaired fast. | Only when an error occurs |
Your browser's network tab shows the same list. Workspace records never travel through these channels.
Service status
Health checks for the public site and the API are published, including when something is degraded.
Check live statusProcurement and security review
Security questionnaires, DPA conversations and review calls go through one channel; a person answers, backed by the same controls this page states.
Contact us
Want the walkthrough first?
The demo workspace is open, no account needed - and pricing is public, including what each plan does not include.