Security & Trust
Your manufacturing data, protected by design

Multi-tenant isolation
Every operational table carries organization_id. Row-level security policies make cross-tenant reads or writes impossible.
Encryption in transit & at rest
TLS 1.2+ everywhere. Database encrypted at rest. Signed URLs for private files.
Granular RBAC
27 default roles, per-module/action permissions, approval rules by value, department and margin.
Immutable ledgers
Posted inventory and financial transactions are append-only. All changes are audited.
Audit trail
Every sensitive action is recorded with actor, before/after data, timestamp and IP.
Permission-aware AI
The copilot follows the user's permissions and never posts transactions without explicit human approval.