Skip to content
FacilCore
Sample access view with a job-scoped contractor and an audit log line

Trust and security

Governance you can put in front of an auditor.

Isolation, least-privilege access and an audit trail are the foundation, not a later add-on.

Platform controls

Access is authenticated, authorised and audited.

Three controls apply to every user and every module on the platform.

Authentication

All users must authenticate before accessing any platform resource, with secure session management behind it.

Authorisation

Role-based access control with contextual rules. Every action is checked against role, scope and assignment.

Audit logging

Security-relevant events are logged and retained centrally: authentication, access and changes alike.

Multi-tenancy

Isolation between clients is enforced, not assumed.

Running multiple clients on one platform demands controls that keep each tenancy to itself. These are enforced at the application and data layers on every request.

Tenant context enforcement

Every request executes within an authenticated tenant context. Cross-tenant access is denied by default.

Domain-level segmentation

Data objects are segmented by domain and evaluated at every access check, preventing lateral movement across portfolios, sites and tenants.

Contractor isolation

External contractors access only the job-scoped data explicitly assigned to them, with no portfolio or tenant traversal.

Access governance

Least privilege and segregation of duties.

Access follows the principles auditors expect to find, applied across every role on the platform.

  • User permissions follow least privilege principles, with role-based assignment and scoped access.
  • Roles are designed to prevent conflicting duties, with approval workflows where separation matters.
  • Role definitions, access reviews and permission change history are available as audit artefacts.

Standards

Aligned with recognised frameworks.

The platform control framework is designed in alignment with ISO 27001 and SOC 2 principles: accountability, traceability and least-privilege access. Evidence artefacts such as role matrices, access logs and retention policies are maintained against each control.

  • Data encrypted in transit and at rest.
  • Regional data residency options where regulation requires it.
  • Private deployment available for strict data governance environments.

Detailed control documentation is available to clients and partners under the appropriate agreements. Request it through our team.

Put your security questions to us directly.

Bring your assurance, procurement or governance requirements and we will walk through how the platform meets them.