adMYTT
Log inBook a demo
Security & trust

Each company gets its own isolated workspace

Customer records and documents are workspace-scoped. Access is role-based, sessions expire and can be revoked, and important actions are written to an audit log. Here is exactly what we operate — and what we don't claim.

Book a demoRead the FAQ
Controls we operate

Protections, described accurately

WS
Isolated workspaces
Each company’s records and documents are scoped to its own workspace.
RB
Role-based access
Staff see only what their role allows — down to assigned leads.
PD
Private document storage
Files are stored privately and access is workspace-scoped.
SE
Secure sessions
Browser sessions are hashed, expiring, and revocable.
AL
Audit logs
Important actions are recorded and reviewable.
SA
Bounded support access
Platform support access is reason-bound, time-limited, and audited.

How each control works

Workspace data isolation
Each customer company operates in its own isolated workspace. Customer records and documents are scoped to that workspace and are never shared across customers. There is no shared, cross-tenant view of records.
Roles & permissions
Access is role-based. You decide what each role can see and do — counsellors can be limited to assigned leads, while owners and admins keep the wider view. Permissions are enforced server-side, not just hidden in the interface.
Authentication & sessions
Browser sessions are hashed, expiring, and revocable. You can end active sessions, and sessions expire rather than persisting indefinitely.
Private document storage
Uploaded files are stored privately and access is workspace-scoped. Documents are not served from public, guessable URLs.
Audit logs
Important actions are recorded and reviewable, so you can see what happened on a record and who did it.
Bounded support access
Platform support access to a workspace is reason-bound, time-limited, and audited. Support does not hold standing access to your data.
We deliberately avoid phrases like “bank-level security” and “enterprise-grade” without defined controls. If you need specific documentation for a procurement review, ask during your demo.

Security FAQ

Do you hold SOC 2, ISO 27001, or GDPR certification?
We describe the controls we actually operate. We do not claim SOC 2, ISO 27001, GDPR certification, or other compliance unless it has been formally verified and documented. Where a control is in progress, we say so plainly.
Can we export our data and security evidence?
Yes. Your data stays yours and remains exportable. Audit logs let you review important actions on your records.
Who at adMYTT can access our workspace?
Only people you invite within your company, plus bounded platform support access that is reason-bound, time-limited, and audited.
How do we report a security concern?
Email demo@admytt.com and ask for the security team, or use your in-product support channel. We will acknowledge and investigate reported issues.

Run a security review with us.

Book a demo and we'll walk your team through workspace isolation, roles, sessions, and audit logs in the product.

Book a demoLog in