ProductSolutionsSecurityPricingResourcesAboutLog inRequest a demo
Security & trust

Built for buyers who read the security questionnaire.

You're handing us the operational record for a real estate portfolio — work orders, leases, vendors, and the people attached to them. Here's exactly how we keep it isolated, scoped, and recoverable.

Microsoft 365 SSO
Row-level tenant isolation
Server-side RBAC
Validated ingestion
Append-only audit log

Per-tenant isolation

Every client is a separate tenant with its own data, branding, and property categories — and the separation is enforced in the database itself with row-level security, not by application code remembering to filter.

Purpose-built roles & scoping

Admin, Property Manager, Tenant and Vendor, plus branch-scoped Bank Manager and Bank Requestor. Access is scoped by category, property, or branch and enforced server-side, not hidden in the UI — a user scoped to one branch cannot query another's data.

Microsoft 365 / Entra ID SSO

Staff sign in with Microsoft 365 / Entra ID single sign-on — no separate password to manage, rotate, or leak — and deprovisioning in your directory cuts access here too. Accounts outside the directory use email and password, and the login method is chosen automatically from the email domain. A trusted external directory can be recognized too, so a client's own users sign in with their own identity.

Hardened sessions & transport

Sessions ride in httpOnly cookies that page scripts can't read, over strict transport security (HSTS), with a content security policy and related modern security headers. Third parties and vendors get scoped, invite-only accounts — no shared logins.

Validated imports & backups

Imports are validated against the category schema before anything is written, and malformed rows are rejected with row-level errors. Backups run automatically, restores are per tenant, and a re-import during go-live takes a snapshot first — so bad data can't poison reports and nothing is one mistake from being lost.

Append-only audit log

Imports, access changes, and role assignments are written to an append-only log — entries are added, never edited away. You can always answer who imported what and who could see it. We follow SOC 2-oriented practices; we don't claim a certification we don't hold.

The short version

Hidden ≠ secure. We block at the query.

Plenty of tools "scope" access by hiding tabs. Bedrok Pro scopes at the data layer with row-level security — the same request from two different roles returns two different result sets, decided in the database. That's the line buyers care about, so it's the line we hold. We follow SOC 2-oriented practices and will walk your team through the detail; what we won't do is claim a certification we haven't earned.

Need our security details?

We're happy to walk your team through architecture, access, and data handling.