Access control
Roles decide what each person can see and do. Access is granted deliberately and can be revoked immediately, including for staff who leave.
Two-factor and 2-step
Authentication app, email or SMS codes, or passkeys where the devices support them. Enforced for admin accounts as standard.
Encryption
Encrypted in transit and at rest. Passwords hashed, never stored or recoverable in readable form, by us or by anyone.
Lawful basis and consent
What you collect, why, and what the person agreed to, captured at the point it happens and kept as evidence rather than assumed.
Retention and deletion
Data that ages out on the schedule you set, and a real delete when somebody asks for one, including from backups within a stated window.
Audit trail
Who logged in, who changed what, who downloaded which file, and when. Dull until the day you need it, and then the only thing that matters.
Backups and recovery
Automatic backups, tested restores, and a written answer to what happens when something breaks at the worst possible moment.
Where data lives
Hosting chosen so your data sits in the region your obligations require, with the processors named for your privacy policy.
We build to the standard and document what we have done, which is the part most suppliers skip. What we do not do is sign off your policies or act as your data protection officer: those stay with you and, where it matters, your legal advisers. Our job is to make sure the system supports your obligations instead of quietly working against them. If your industry answers to a specific framework, say so at the scoping stage and we build to it.
Portals are usually wired into the tools you already run, and the workflows that feed them are the same ones covered on the AI and automation page.