Defense in depth, on every plan.
Security isn't a tier you upgrade to. Every organization gets the same isolation, access control and audit trail from day one.
Org-level data isolation
Every query is scoped to your organization at the data layer. Multi-org users never see across boundaries — enforced, not just configured.
Attribute-based access control
Fine-grained ABAC — attribute policies, department scoping and data-sensitivity tiers — with role-based access (RBAC) underneath.
Step-up MFA on sensitive actions
High-risk actions demand a fresh authentication challenge. A stolen session isn't enough to move money or export data.
Full, exportable audit trail
Every action — human or AI agent — is logged with who, what and when. Access reviews and retention controls are built in.
Governed, grounded AI
Agents act through the same access policies as people, behind an approval queue. Every AI output is independence-checked before it reaches you.
Your data stays yours
Org-isolated, encrypted in transit and at rest, never sold, and never used to train third-party models.
Built for real organizations — not a role dropdown.
Full attribute-based access control so multi-entity and multi-department teams can run the business on one platform without oversharing.
Full ABAC on every plan — Team, Business and Enterprise. Plans differ by support, compliance ops and scale, not by locking access control.
Built to the standards that matter.
We name what we actually ship — and we refuse certifications or badges we have not earned.
Security questions, answered honestly.
We build to SOC 2 and ISO 27001 control standards. We do not claim a third-party certification we don't currently hold — when that changes, we'll say so here.
Never for third-party foundation models. Customer Data is not sold and is not used to train models we don't own. See the Privacy Policy.
Full ABAC is on every plan. Business adds packaging and ops support around governance at scale — not a lock on the control itself.
Yes. A public Data Processing Addendum is at /legal/dpa; sub-processors, privacy and terms are under /legal. Contact us for early access, a countersigned DPA (SCCs where required), or a security review.
The first agentic ERP.
Request early access.
Join early access to the first ERP built for humans and agents on one governed platform. Full ops suite live today — public release targeted for September 1, 2026.