Account controls
Password hashing, session regeneration, optional MFA, role permissions, CSRF controls and Cloudflare Turnstile support protect authentication and sensitive actions.
Tenant isolation
Agency-scoped records and permission checks are used throughout the application so one agency cannot intentionally browse another agency’s operational data.
Operational monitoring
Rate limiting, audit logs, system-health checks, integration-job logs, backup records and security-event tracking support investigation and recovery.
AI health monitoring
OpenAI may analyse structured health evidence when enabled, but automated repairs are limited to predetermined allowlisted actions. Arbitrary model-generated PHP, SQL, credential, payment or permission changes are not executed.
