Security & trust

Built to pass the security questionnaire

SSO and SOC 2 are the two hard gates in enterprise procurement. We're built to clear them — with federated identity, provable data lineage, and an audit trail regulators and auditors both accept.

Identity & access

Your identity provider, your rules

Federate the directory you already run, automate the joiner-mover-leaver lifecycle, and scope every user to exactly what they should see — and nothing more.

OIDC single sign-on live

Federate your own identity provider. Users sign in with credentials your organization already controls; you own the passwords and the MFA policy. We run this in production on Microsoft Entra. SAML 2.0 is implemented to spec but has not yet been run against a live IdP — if you need it, you would be our first, and we would prove it in your sandbox first.

SCIM 2.0 provisioning not yet IdP-proven

Automated user lifecycle from your directory — accounts created, updated, and deprovisioned on offboarding without a manual ticket. The endpoint is built and tested against the SCIM 2.0 spec, but no customer has yet connected a live directory to it. Today, roster changes come in by CSV/XLSX import. We are not going to tell you a connector is battle-tested when it has never met your Okta.

Full role-based access control

Least-privilege roles, per-site scoping, and strict multi-tenant isolation. A supervisor sees their site; a corporate lead sees the roll-up; a contractor sees only what the gate lets them. No shared blast radius between tenants.

The audit trail

A record you can prove, not just point to

The audit log is tamper-evident and cryptographically signed. Every change is attributable to a specific user at a specific time — and it's exportable whenever you need it. It doubles as the OSHA 1910.1020 employee access-to-records log, and electronic records kept in a secure, non-alterable system are explicitly accepted by MSHA's workplace-exam rule for regulatory recordkeeping.

  • Tamper-evident & signed — content-hashed entries make silent edits detectable.
  • Attributable — every change tied to a user and a timestamp.
  • Exportable — pull the full trail on demand, no gatekeeping.
  • OSHA 1910.1020 access log — doubles as the required record-access history.
  • Accepted for regulatory recordkeeping — a secure, non-alterable system meets MSHA's workplace-exam rule.
Compliance posture

Where we stand — stated plainly

This is a trust page, so accuracy matters more than marketing. Here is exactly where our compliance program is today.

SOC 2 Type II In progress

SOC 2 Type II is the de-facto enterprise procurement gate, and our program is actively underway. To be clear: this is a roadmap item — we are not yet certified and will not claim otherwise. We're happy to share our current status and timeline under NDA.

Data residency

Your data is hosted in US Azure regions by default. Infrastructure runs on Microsoft Azure with encryption in transit and at rest, in a single, well-understood cloud footprint.

Health-data handling

Occupational-health and medical-surveillance data is handled to OSHA 1910.1020: medical records retained for employment plus 30 years, exposure records for 30 years, with consent-gated access. Where a customer is a HIPAA covered entity and needs one, we're ready to sign a BAA.

  • Suggests, never decides — the assistant drafts; a person signs off.
  • No auto-classification of recordability — a judgment the law requires a human to make.
  • Constrained & grounded — outputs are structured and tied to your records, not free-form guesses.
  • Logged both ways — the AI suggestion and the human decision are both in the audit trail.
Responsible AI

The AI suggests. A human decides.

Our incident-intake assistant drafts classifications and corrective actions and flags likely recordability — but it never makes the call. Recordability carries judgment-laden criteria that legally require a human decision, so a person always signs off.

Outputs are constrained, structured, and grounded in your own data rather than open-ended generation. And the split between the AI's suggestion and the human's decision is written to the audit trail, so you can always see who decided what. Honest framing isn't a footnote here — it's the whole point.

Your data stays yours

No lock-in — leave whenever you like

Your safety record is your asset, not our hostage. Everything you put in, you can get back out.

Exportable audit logs

Pull the full, signed audit trail on demand for your own retention, e-discovery, or regulator requests.

BI & CSV extracts

Export your incidents, actions, training, and exposure data to CSV or your BI stack whenever you need it.

Read API

Programmatic read access lets you sync records into your own systems on your schedule — no manual re-keying.

Trust FAQ

The questions security teams ask

Are you SOC 2 certified?

Not yet — and we won't claim to be. Our SOC 2 Type II program is in progress. It's a roadmap item we're actively working toward, not an achieved certification. We're glad to walk through our current status and timeline with your team under NDA.

Do you support SSO?

OIDC: yes, in production today. Customers federate their own identity provider and sign in with credentials their organization already controls — we run this on Microsoft Entra ourselves.

SAML 2.0 and SCIM 2.0: built, but not yet proven. Both are implemented against the standards and covered by tests, but neither has been exercised against a live Okta or Entra tenant — no customer has needed it yet. If you do, you would be our first: we would stand it up jointly in your sandbox and prove it before you signed anything. We would rather tell you that now than discover it together during implementation.

Where is our data stored?

In US Azure regions by default, on Microsoft Azure infrastructure, with encryption in transit and at rest.

Can we get an audit-log export?

Yes. The tamper-evident, signed audit log is exportable on demand — every entry attributable to a user and timestamp — for your own retention or to satisfy a regulator or auditor.

Do you sign BAAs?

Where a customer is a HIPAA covered entity and needs one, yes. Occupational-health and medical data is already handled to OSHA 1910.1020 retention and consent standards.

Have a security questionnaire? We're ready for it.

Send us your requirements, or see the platform's identity, audit, and data controls running on scenarios that look like your operation.