Skip to content
Home · Security & trust

Built with control at its core.

You're trusting iQuotient with your documents, your evidence and (if you run ISO 27001) your ISMS. Here's how the platform is built to protect it, and how to get what your security team needs.

Access & authority

Visible never means permitted.

Access isn't cosmetic. Permissions are enforced on the server, by module and by site. Denied actions are removed, not just hidden in the page.

Role-based, server-side

Every action is checked against the user's module and site permissions before anything is shown or done.

Consultant authority lane

Platform-level authority stays with your Synergy Consilium consultants: tenant users are operators, not administrators.

Portal boundaries

Supplier and customer portal users never see internal modules; internal users never see portal-only data.

Defense in depth

Control in layers, not a single lock.

Hover or tap a layer. Protection is enforced from the perimeter inward, so your management-system data sits behind several independent controls.

Record & evidence integrity

Records that hold up: protected end to end.

Evidence-gated

Records carry their lineage and evidence; non-conformances can't close without root cause and an effectiveness review.

CSRF protected

State-changing actions are protected against cross-site request forgery, with strict server-side validation.

Guarded sessions

Early authentication gates and session controls protect every route before any data is touched.

Time-limited file access

Evidence files are served through short-lived, scoped access tokens, not open links.

Isolation & data

Single-tenant by design.

Each client runs in its own isolated environment, with its own database. Your management-system data is not co-mingled with other organisations'. The system is scoped to your standards, sites and people from the moment it's set up.

Handled under POPIA.

Personal information on this site and in your enquiries is handled in line with South Africa's Protection of Personal Information Act. See our Privacy notice for how we use cookies, analytics and enquiry data.

Doing a security review?

If your team runs vendor due diligence, we'll provide a security overview and our data-processing terms on request, covering hosting, data handling, access control and our response process. Just ask when you book a demo, or contact us directly.

Run your system on a platform built to be trusted.