Organisation isolation
Every record is scoped to your organisation. Isolation is enforced in the application and verified in our tests — not a configuration you have to remember to set.
Cyber Toolbox holds the evidence, decisions and regulator clocks for your most sensitive work. Here is how that is kept isolated, access-controlled and auditable — in plain language.
In active development (alpha) — we position our posture honestly
Every record is scoped to your organisation. Isolation is enforced in the application and verified in our tests — not a configuration you have to remember to set.
Evidence is hashed, the collector is recorded immutably, and every access is logged. Operator actions and billing changes land in an append-only audit trail — the foundation for answering “who did what, when”.
Sign in with email one-time codes, passkeys, or an optional authenticator-app 2FA — with step-up auth required on high-consequence actions.
Access is governed by role, so people see and do what their role allows — and high-consequence actions are gated and logged.
Enterprise customers can front their organisation with their own SSO / IdP, so access follows your existing identity controls and joiner-mover-leaver process.
Audit trail, access controls and change-management discipline are designed with SOC 2 in mind. We are in active development (alpha/beta) and say “maturing toward SOC 2 readiness”, not “certified”, until certification exists.
Send us your security questionnaire or due-diligence request and we’ll work through it. You can also read our security.txt.