Security is a data-model decision, not a settings page
Isolation, access control and audit are enforced in the database. That is the only place an application cannot accidentally bypass them.
Last reviewed: August 2026. This page states what we do not yet hold as well as what we do.
How it is enforced
Tenant isolation at the row
Every record carries a tenant identifier and is covered by a database-enforced row-level security policy. A query cannot return another tenant's row, whatever the application code asks for.
Role-based access control
Roles are stored separately from user profiles and evaluated server-side. Permission is never inferred from anything the browser can change.
Append-only audit trail
Who changed what, when, and from what value. No role — including administrators — can edit or delete audit history.
Your data stays yours
Full export on every plan, including Free. Migration in from MS Project, Primavera, Jira, Smartsheet, monday.com and Asana is included, not sold as services.
Residency and sovereignty
Regional data residency options, plus a Sovereign tier deployed in your own data centre or private cloud with full residency control.
Source escrow option
Regulated, government and utility customers can take a source escrow arrangement alongside the self-hosted deployment.
Residency manifest
Where your records are stored, where they are processed, and where AI inference runs. All three, stated separately — a residency claim that covers storage but not inference is not a residency claim.
- European Union
- Storage
- EU region
- Processing
- EU region
- AI inference
- EU region
Default for new tenants.
- Middle East
- Storage
- Middle East region
- Processing
- Middle East region
- AI inference
- Middle East region
Selected at tenant creation.
- United States
- Storage
- US region
- Processing
- US region
- AI inference
- US region
Selected at tenant creation.
- Sovereign (self-hosted)
- Storage
- Your data centre or private cloud
- Processing
- Your infrastructure
- AI inference
- Your infrastructure, or disabled entirely
Per-tenant schema isolation, source escrow available.
Controls and certifications
5 of 9 listed below are in place today. The rest say “not yet held” rather than being left off the page — the gap surfaces in due diligence anyway, and you should hear it from us first.
- Row-level tenant isolationEnforced by database policy, not application code.
- Encryption in transit and at restTLS in transit; encrypted storage at rest.
- Append-only audit loggingImmutable, exportable, retained per policy.
- SAML SSO and SCIM provisioningEnterprise plan.
- Regional data residencyEU, Middle East and US, plus self-hosted.
- SOC 2 Type IINot yet held. No audit period has completed.
- ISO/IEC 27001Not yet held. Controls are modelled on it; the certification is not in place.
- ISO/IEC 27018Not yet held.
- Independent penetration test reportNot yet available for public distribution.
Platform capabilities in full
All 14 platform and security capabilities, with the lowest plan that includes each.
- SSO / SAML / SCIM provisioningEnterprise
Single sign-on via SAML or OIDC against the corporate identity provider, plus SCIM automated user provisioning and de-provisioning driven by directory group membership.
- Granular role-based access controlProfessional
Permission control at object, field and record level, driven by role, group and relationship to the record - not just coarse tiers of read, write and admin.
- Configuration without codeEnterprise
The ability to change object models, fields, layouts, workflows, lifecycles, permissions and reports through administrative configuration rather than development or vendor services.
- ERP integration (SAP / Oracle)Enterprise
Pre-built or supported integration with the corporate ERP for cost actuals, commitments, purchase orders, cost centres, vendors and employee master data.
- MS Project / Primavera importProfessional
Import and where relevant round-trip of schedules from Microsoft Project (.mpp, XML) and Primavera (XER, P6 XML), preserving structure, dependencies and resource assignments.
- Native BI & analyticsProfessional
Built-in reporting and analytics - custom report building, cross-object queries, calculated fields, visualisation and scheduled distribution - without an external BI tool.
- Power BI / Tableau connectorEnterprise
A supported connector or data warehouse feed exposing the underlying data model to external BI tools.
- AI assistant or agentic featuresProfessional
Embedded AI - natural-language querying, generated status narrative, risk prediction, document summarisation - and agentic capability that takes actions rather than only producing text.
- Audit trail & compliance loggingFree
Immutable logging of every material action - who changed what, when, from what value to what value - retained per policy and exportable for audit.
- Open REST APIProfessional
A documented, versioned REST API covering read and write across the object model, with authentication, rate limits and webhooks for event-driven integration.
- Regional data residency optionsSovereign
The ability to specify where data is stored and processed, including which cloud regions are offered and where AI processing occurs.
- On-premise / private cloud optionSovereign
Availability of a self-hosted or private-cloud deployment rather than multi-tenant SaaS only.
- Arabic UI / RTL supportFree
Full Arabic interface localisation with proper right-to-left rendering, plus Arabic content entry, search, sorting and correct rendering in reports and exports.
- Published implementation partner networkStarter
The availability of certified implementation partners, and specifically whether any operate in or near your region with local-language capability.
Send us your security questionnaire
DPAs, residency questions and due-diligence packs are handled by the same team that built the isolation model.
