Two-factor authentication
A second factor for every customer role
A second factor is mandatory for administrators, risk managers and auditors. Access to the protected workspace is withheld until two-factor authentication has been set up.
NISBee combines role-based access, mandatory two-factor authentication, tenant-bound data processing and traceable changes in a browser-based cloud application.
Access & identity
Roles, session context and organisation context are evaluated on the server before protected application functions become available.
Two-factor authentication
A second factor is mandatory for administrators, risk managers and auditors. Access to the protected workspace is withheld until two-factor authentication has been set up.
Role model
NISBee distinguishes between administrators, risk managers and auditors. Operational and administrative permissions are assigned by role.
Read-only
Auditors can review audit-relevant content and reports. Write operations are blocked on the server.
Organisation context
The organisation context is taken from the authenticated session, not from freely supplied form or URL values.
Cloud operations & tenant isolation
NISBee is delivered centrally as a web application. No separate client installation is required on individual workstations.
Application data is processed in an organisation-bound context and separated at database level using PostgreSQL Row-Level Security.
No application data is visible without a valid organisation context.
In addition to Row-Level Security, every application query is explicitly bound to the organisation in the authenticated session.
Protection layer: application + database
Traceability
Application changes are logged on the server. The actor and timestamp come from the application session and are processed in the same transaction as the respective change.
Risk / measure / evidence / incident
Responsible role
Named user
Operational state and change log
The change log supports operational traceability and does not replace an external immutable archive.
Technical trust facts
Field-level encryption
Selected sensitive free-text fields are encrypted at field level before storage.
AES-256-GCM
Organisation-bound keys
Encryption keys are derived per organisation from a centrally managed master key.
HKDF-SHA256
Row-Level Security
The database restricts access to data belonging to the currently active organisation.
Least privilege
The application, platform functions and database migrations use separate permission contexts.
Web security
The cloud application uses controls including HSTS, Content Security Policy, frame protection and nosniff.
Authentication protection
Authentication routes are rate-limited on the server; password resets revoke existing sessions and accounts use email verification.
Export, backup & evidence
Documented information can be exported in structured formats, backed up and reused for internal reviews.
Export structured data for backup and further processing.
Prepare tabular information for internal analysis.
Prepare and output the documented state as a report.
Validate and import structured datasets and manage them as a backup state.
The evidence centre structures and references evidence; it is not a general-purpose document archive.
Scope & Responsibility
Clear classification: The NIS2 Risk Manager supports structured NIS2 risk management without providing legal advice, certification or automatic assurance of compliance.
Contact
We answer questions about the operating model, data handling and evaluation in concrete terms – in writing for your internal review if needed.