Encryption and Security at Every Layer

Encrypted at Rest

The agent’s local database is AES-256 encrypted with machine-bound keys. The database is not readable without those unique agent keys.

Encrypted in Transit

All agent data is double-encrypted: application-layer AES-256-GCM encryption on top of TLS transport encryption. Agent payloads stay encrypted even where TLS is terminated at a load balancer or CDN edge.

Secured at Portal

Role-based access control, MFA on all accounts, CSRF protection, secure cookies, session regeneration, and full admin audit logging.

Key Management

Encryption keys are machine-bound and never stored in plaintext. Per-agent keys are derived cryptographically.

Role-Based Access Control

Role Capabilities
Viewer Read-only access to dashboards and activity pages. Cannot export data or manage users.
Manager Dashboard access plus data export (CSV, JSON, PDF, DOCX). Cannot manage agents or configuration.
Admin Full access: user management, agent configuration, data export, and organisation settings.

Multi-Factor Auth

TOTP authentication on all accounts. Trusted device management for reduced friction.

Admin Audit Trail

Every login, configuration change, user modification, and data export is recorded.

Data Retention

Configurable retention periods per organisation. Automatic cleanup of expired data. Legal holds available.

Configurable Scope

Every module can be individually enabled or disabled per agent. Collect only what your organisation needs.

Full Transparency

Methodology modals on every dashboard explain exactly how scores are calculated. No black boxes.

Tiered Access

Sensitive features like AI prompt capture and screenshots are only available on higher-tier plans.

Data Isolation

Dedicated per-organisation databases provide complete tenant separation. No shared data stores.