How access and data are protected.
Tenant isolation
Every organization's data is scoped by row-level security enforced at the database layer — not just filtered in application code, which a bug could bypass.
Encryption in transit
All traffic between your browser or device and OrgView is encrypted over HTTPS/TLS.
Encryption at rest
The underlying managed database platform encrypts stored data at rest.
Role-based access control
A 7-role permission matrix, enforced both in the interface and again server-side — page access, budget/profit visibility, and report scope all vary by role.
Password authentication
Email and password sign-in. Current minimum length is short by enterprise standards — a stronger policy (12+ characters, complexity rules) is planned, not yet enforced.
Multi-factor authentication
Not yet available. On the roadmap.
Single sign-on (SSO / SAML / OIDC)
Not yet available. Planned for organizations that require centralized identity management.
Vulnerability & error monitoring
Production errors are captured and triaged by an application monitoring service before they affect a team relying on the page.
Backup & disaster recovery
Data is held on a managed database platform with provider-level backups. A formal, tested, and documented RPO/RTO policy is not yet published.
How actions and changes are controlled.
Audit log
An immutable record of governance-sensitive actions — team invites and every posted financial entry. Coverage is expanding module by module; it is not yet a record of every action in the system.
Segregation of duties
Role permissions distinguish who can view budget/profit information, who can post financial entries, and who can invite team members (director-only, checked server-side).
Permission matrix
Seven distinct roles, each with an exhaustive, explicit page and capability list — nothing is accessible by default that isn't explicitly granted.
Financial posting controls
Real double-entry bookkeeping — every posted entry is logged. Formal multi-step approval workflows for postings are not yet built.
Document & drawing revisions
Technical drawings and documents are tracked per project with revision labeling in the Technical module.
Ownership, hosting, and your rights over your data.
Data ownership
Your organization's data is yours. OrgView is the processor of it, not the owner.
Hosting
Data is hosted on a managed cloud database platform; the web application is served via a global content delivery network.
GDPR & Data Processing Agreement
A published DPA, formal subprocessor list, and documented data retention/deletion policy are not yet available — in progress ahead of enterprise contracting.
Data export
Commercial data exports to Excel; quotes, client packs, and finance documents export to PDF today. A general-purpose full data export/portability tool is not yet built.
Subprocessors
Third-party services genuinely in use: a managed database/auth provider, Microsoft (for Outlook mail sync, via your own OAuth consent), Companies House (UK company data), and Stripe (payment confirmation). A formal published subprocessor list is on the roadmap.
What we hold today, and what we're pursuing.
OrgView does not currently hold Cyber Essentials Plus, ISO 27001, or SOC 2. We're not going to claim otherwise. As these are achieved, they'll be published here — not before.