Skip to content
Teftiş Go
Menu

Security starts with knowing who can reach each record—and when.

Teftiş Go limits access by Organisation, Role and Location scope. This page describes only controls verified in the product and the boundaries around them.

  1. Organisation isolation

    Every request is authorised within its Organisation. The data layer applies the same tenant boundary, and cross-organisation access is covered by automated tests.

    Isolation is enforced in application authorisation and data scope.

  2. Roles and scope

    Roles and Permissions define what a User can do. Location and group scope define which records that User can see. A permission does not make the entire Organisation visible by itself.

    User, Role and scope are evaluated together.

  3. Completed Audit records

    Published Template Versions and completed Audit snapshots are not silently rewritten. An approval result creates a new report revision instead of replacing the previous report.

    Immutability applies to named published and completed records—not to every record in the system.

  4. Evidence access

    Evidence uploads are checked against permitted file types, size limits and file digests. Downloads use short-lived links after an access check; files do not have permanent public URLs.

    The product does not claim end-to-end encryption or security certification.

Make your enterprise requirements concrete.

SSO, custom integrations and contractual service levels are not standard product capabilities; they are evaluated as part of an Enterprise proposal.

Send a security question