Back to Home
Enterprise Security

Platform Security

At PermitMe, safety and cybersecurity are our foundational principles. Our platform is engineered with enterprise-grade controls to ensure your operational data remains secure, private, and always available.

Infrastructure & Hosting

  • Cloud Provider: Hosted exclusively on Google Cloud Platform (GCP), leveraging their ISO 27001 and SOC 2 compliant infrastructure.

  • Data Sovereignty: Customer data can be hosted in your desired geographical region, ensuring local data residency and compliance with regional laws.

  • Tenant Isolation: Each client operates within a dedicated, completely isolated cloud project, ensuring full physical segregation of your database and application layers from other tenants.

Data Protection

  • Encryption: All data is encrypted in transit using TLS 1.2+ and at rest using AES-256 encryption.

  • Data Ownership: Clients retain full ownership of their data. We only process data to deliver the service and collect high-level, anonymized metrics for platform improvement.

  • Custom Data Exports: If required, we can configure automated, scheduled data exports directly to your own preferred local servers or cloud storage (e.g., SharePoint).

  • Key Management: Encryption keys are securely governed using Google Cloud Secret Manager with strict access controls.

Access & Identity

  • Single Sign-On (SSO): Native support for Microsoft Entra ID (Azure AD). PermitMe is a verified Microsoft Publisher.

  • Multi-Factor Authentication: Enforceable via your SSO provider, with alternative MFA options available for external contractors.

  • Role-Based Access (RBAC): Granular, configurable permission models ensuring least-privilege access across administrators, issuers, and end-users.

Auditability & Testing

  • Immutable Audit Logging: Tamper-resistant, server-side audit trails for all critical actions (permit creation, edits, approvals, system access).

  • Penetration Testing: Comprehensive third-party vulnerability assessments conducted annually, supplemented by weekly automated scans.

  • Patch Management: Critical vulnerabilities are remediated and patched seamlessly, typically within 24 hours.

Reliability & Business Continuity

  • Uptime & Availability: We maintain a 99.5% uptime SLA, historically achieving over 99.9% availability over the past three years.

  • DDoS & WAF: Multi-layered protection via Google Cloud's global edge network, with Web Application Firewall (Cloud Armor) options.

  • Automated Backups: Point-in-time recovery (7 days retention), daily snapshots (14 days), and weekly snapshots (30 days).

  • Disaster Recovery: Target 12h RTO and 24h RPO, validated through regular disaster recovery and restoration exercises.

Have your own security questionnaires or due diligence requirements?

We understand that enterprise IT and cybersecurity teams have specific evaluation criteria. We are happy to provide details and answer any specific questions your team might have to confidently approve PermitMe.

Contact our Security Team