Loading

Trust SOC 2 Type II report available on request

The control plane for regulated enterprise work

Govern access, automate approvals and prove compliance from one platform, with the security posture your auditors, CISO and board expect.

Independently audited and certified

  • SOC 2 Type IIAudited annually
  • ISO 27001Certified ISMS
  • GDPRDPA included
  • HIPAABAA available
Control plane dashboard with environments, audit log and policy status

Access matrix

Least privilege
RoleReadWriteExportAdmin
Admin
Editor
Auditor
Viewer
SSO enforced: 12,480 users covered

Trusted by security-conscious teams in finance, health and the public sector

Northwind Voltra Evergreen Summit&Co Hexa Loopline
Platform overview

Four pillars. One governed platform.

Every capability shares the same identity layer, policy engine and audit trail, so control scales as fast as your organisation does.

Pillar 01

Policy that is enforced, not just written

Define guardrails once and apply them to every workspace, region and business unit. Changes are versioned, reviewed and reversible.

  • Central policy library214 prebuilt controls mapped to common frameworks.
  • Change approvalsTwo-person review for sensitive configuration changes.
Policy status table listing enforced security policies, scope, owner and status
Pillar 02

Every identity verified, every permission justified

Connect your identity provider, provision users automatically and give people only the access their role requires.

  • SSO and SCIMSAML 2.0, OIDC and automated joiner-mover-leaver.
  • Role-based accessCustom roles with time-bound, reviewable grants.
Identity providers panel with SSO, directory sync and MFA coverage
Pillar 03

Approvals and runbooks that document themselves

Replace email chains with routed workflows. Each step records who decided what, when and why, ready for the next audit.

  • Risk-based routingSend high-risk requests to the right approvers automatically.
  • Complete evidenceEvery decision is stored with its context and timestamp.

Access request

Submitted by a manager

Risk review

Score above 70

Granted and logged

Expires in 14 days

Security approval

If risk is high

Notify channel

#access-reviews
Pillar 04

See reliability and risk before they become incidents

Track service levels, usage and unusual behaviour across the whole organisation, then stream the signals into your own tooling.

  • Service-level reportingUptime and latency by region, ready for your review board.
  • SIEM streamingForward audit events in real time to your security stack.
Observability dashboard with uptime, p95 latency, request volume and regional SLA
Security & compliance

Security you can verify, not just trust

Controls are monitored continuously and tested independently. Request our reports under NDA at any time.

AES-256 at rest TLS 1.3 Customer keys Zero trust
Enforced

Encryption everywhere

AES-256 at rest and TLS 1.3 in transit, with optional customer-managed keys.

Enforced

SSO and MFA

Mandatory strong authentication with phishing-resistant options.

Active

Data residency

Keep data in the region you choose, across 14 hosting locations.

Active

Immutable audit logs

Tamper-evident records retained for up to ten years and exportable.

Monitoring

Vulnerability management

Continuous scanning with defined remediation times for every severity.

Quarterly

Third-party penetration tests

Independent testers probe the platform and share results with customers.

Certifications and attestations

  • SOC 2 Type IISecurity, availability, confidentiality
  • ISO 27001Information security management
  • ISO 27017 / 27018Cloud and privacy controls
  • GDPRData processing addendum
  • HIPAABusiness associate agreement
Enterprise features

Built for the way large organisations actually work

Six capabilities that procurement, security and IT ask about first, included from day one.

  1. 01

    SSO and SCIM provisioning

    Sign in through your identity provider and keep accounts in sync automatically as people join, move and leave.

  2. 02

    Granular role-based access

    Build custom roles, scope them to teams or regions and review grants on a schedule you control.

  3. 03

    Audit logs with SIEM export

    Every action is recorded and can be streamed to your security tooling in near real time.

  4. 04

    Regional data residency

    Choose where data is stored and processed, with documented sub-processors for each location.

  5. 05

    Dedicated infrastructure

    Run on isolated compute and storage with private networking and your own maintenance windows.

  6. 06

    24/7 support with a named manager

    A technical account manager, a 15-minute response target for critical issues and quarterly reviews.

Security settings panel with SSO, SCIM, IP allowlist and data region toggles
Integrations

Fits into the stack you already govern

More than 200 certified connectors, plus open APIs, webhooks and a Terraform provider for everything else.

Identity

24
  • Microsoft Entra IDSSO and SCIM
  • Google WorkspaceSSO and directory
  • SAML 2.0 and OIDCAny compliant provider
  • SCIM 2.0Automated provisioning

Security

38
  • SIEM streamingSyslog and HTTPS
  • Key managementBring your own key
  • Endpoint postureDevice trust signals
  • Incident toolingPaging and escalation

Collaboration

52
  • SlackApprovals and alerts
  • Microsoft TeamsApprovals and alerts
  • JiraTicket sync
  • GitHubChange evidence

Data and cloud

96
  • AWSStorage and networking
  • SalesforceTwo-way records
  • Data warehousesScheduled exports
  • REST API and TerraformInfrastructure as code
Customer success

Measurable outcomes for regulated teams

Three organisations, three industries and one common result: faster audits with fewer surprises.

Two engineers reviewing code together at a shared desk Summit&Co
Financial services

62%less audit preparation time

Summit&Co replaced spreadsheet evidence with automated control reports across 11 business units.

Read the story
A team meeting around a long table in a bright office Evergreen Health
Healthcare

3.4Mpatient records governed

Evergreen Health enforced least-privilege access in nine weeks without slowing clinical teams.

Read the story
A colleague presenting ideas on a whiteboard to her team Voltra Energy
Energy and utilities

4xfaster access approvals

Voltra routes contractor requests by risk and now closes most of them in under an hour.

Read the story
0%

Uptime SLA, backed by service credits

0+

Enterprise customers worldwide

0

Hosting regions for data residency

<0 min

Response target for critical issues

Executive perspectives

What security and finance leaders say

“Procurement signed off in one cycle. The security documentation answered every question before we asked.”
Portrait of Elena Duarte Elena DuarteChief Information Officer, Evergreen Health
“Predictable pricing, a named manager and an uptime record we can show our board. That is rare.”
Portrait of Martin Voss Martin VossChief Financial Officer, Voltra Energy
Pricing

Plans for every stage of governance

Start with a team plan or talk to us about an enterprise agreement tailored to your requirements.

Monthly Annual Save 18%

Team

For departments that need shared workspaces and solid basics.

$29/ user / month
  • Unlimited workspaces
  • Standard roles and MFA
  • 90-day audit history
  • Business-hours support
Start with Team

Business

For organisations that need SSO, automation and stronger oversight.

$59/ user / month
  • Everything in Team
  • SSO and SCIM provisioning
  • Approval workflows
  • 1-year audit history
  • 24/5 priority support
Start with Business
FAQ

Questions from security and procurement

Need something specific for a vendor review? Our trust team answers questionnaires within five business days.

Yes. Under NDA we share our latest SOC 2 Type II report, ISO certificates and penetration test summaries.

You choose the primary region from 14 locations. Data stays there, and backups remain in the same jurisdiction.

Enterprise plans can bring their own keys from a supported key management service and revoke access at any time.

Connect any SAML 2.0 or OIDC provider in minutes, then enable SCIM to provision and deprovision users automatically.

Enterprise agreements include a 99.99% uptime SLA with service credits and a public status history.

Most organisations go live with a first business unit in four to six weeks, guided by a dedicated implementation lead.

Yes. Data and logs are exportable at any time in open formats, and audit events can stream to your SIEM.

Our legal team works with yours on master agreements, data processing addenda and business associate agreements.

Request a demo

See SaaSyTech against your own requirements

Book a 45-minute walkthrough with a solutions engineer. Bring your security questionnaire and we will answer it live.

  • Tailored to your industryFrameworks and controls mapped to your regulators.
  • Security documentationSOC 2 report and architecture overview shared under NDA.
  • A clear rollout planTimeline, resourcing and success measures in writing.

Tell us about your team

We reply within one business day and never share your details.