Safe by default

Security & Roles

Tenant isolation, server-enforced permissions, session control, audit history, and honest provider boundaries.

The problem it solves

Role checks hidden only in the interface do not actually protect sensitive records.

Who uses it

AdministratorPlatform Operator

Reports included

  • Audit log
  • Login history
  • Session history

How it works

  1. 1Isolate every tenant to its own database and private storage
  2. 2Enforce permissions on the server for every request
  3. 3Manage sessions and revoke access immediately
  4. 4Record an audit trail for important changes

Frequently asked questions

Is tenant data ever shared?

No. Each institution is resolved to exactly one database and one private bucket per request.

Are permissions enforced server-side?

Yes. Role and relationship checks run on the server, not only in the interface.