Security and data control at NISBee

NISBee combines role-based access, mandatory two-factor authentication, tenant-bound data processing and traceable changes in a browser-based cloud application.

Access & identity

Access starts with a verified identity.

Roles, session context and organisation context are evaluated on the server before protected application functions become available.

Two-factor authentication

A second factor for every customer role

A second factor is mandatory for administrators, risk managers and auditors. Access to the protected workspace is withheld until two-factor authentication has been set up.

Role model

Permissions aligned with each task

NISBee distinguishes between administrators, risk managers and auditors. Operational and administrative permissions are assigned by role.

Read-only

Auditors without write access

Auditors can review audit-relevant content and reports. Write operations are blocked on the server.

Organisation context

Access within the organisation context

The organisation context is taken from the authenticated session, not from freely supplied form or URL values.

Cloud operations & tenant isolation

Protection layers work together.

  1. Browser-based delivery

    NISBee is delivered centrally as a web application. No separate client installation is required on individual workstations.

  2. Tenant isolation

    Application data is processed in an organisation-bound context and separated at database level using PostgreSQL Row-Level Security.

  3. Fail-closed

    No application data is visible without a valid organisation context.

  4. Two layers of control

    In addition to Row-Level Security, every application query is explicitly bound to the organisation in the authenticated session.

    Protection layer: application + database

Traceability

Trace changes. Document responsibilities.

Application changes are logged on the server. The actor and timestamp come from the application session and are processed in the same transaction as the respective change.

Capture

Risk / measure / evidence / incident

Operational review

Responsible role

Change / approval

Named user

Traceable status

Operational state and change log

  • Timestampserver-generated change time
  • Useracting person from the session
  • Objectaffected application entity
  • Actioncreate, update, delete or domain event
  • Descriptionoperational context of the change
  • Before / afterwhere provided for the respective operation
Approval:OpenIn reviewApproved

The change log supports operational traceability and does not replace an external immutable archive.

Technical trust facts

Protection where sensitive information is processed.

Field-level encryption

Protect sensitive free text at rest

Selected sensitive free-text fields are encrypted at field level before storage.

AES-256-GCM

Organisation-bound keys

A key context for each organisation

Encryption keys are derived per organisation from a centrally managed master key.

HKDF-SHA256

Row-Level Security

Tenant isolation in PostgreSQL

The database restricts access to data belonging to the currently active organisation.

Least privilege

Separate database roles

The application, platform functions and database migrations use separate permission contexts.

Web security

Restrictive browser security policies

The cloud application uses controls including HSTS, Content Security Policy, frame protection and nosniff.

Authentication protection

Protected sign-in flows

Authentication routes are rate-limited on the server; password resets revoke existing sessions and accounts use email verification.

Export, backup & evidence

Your documentation remains controllable and exportable.

Documented information can be exported in structured formats, backed up and reused for internal reviews.

JSON export

Export structured data for backup and further processing.

CSV export

Prepare tabular information for internal analysis.

PDF / print report

Prepare and output the documented state as a report.

Import & backup

Validate and import structured datasets and manage them as a backup state.

  • Typekind of evidence
  • Referencelinked risk, measure or supplier
  • Statuscurrent operational state
  • Ownerassigned person or role
  • Valid untildocumented validity date
  • Next reviewscheduled review date
  • Locationreference to the documented evidence

Scope & Responsibility

Clear responsibility instead of false promises.

Clear professional boundaries

  • NISBee does not replace legal advice.
  • NISBee does not provide an automatic assurance of compliance.
  • NISBee does not replace an authority's assessment or classification.

Responsibility remains with the organisation

  • Operational decisions and approvals remain with the organisation.
  • Evidence can be documented and referenced in a structured way.
  • NISBee is not a general-purpose immutable archive.

Contact

Questions about security or deployment?

We answer questions about the operating model, data handling and evaluation in concrete terms – in writing for your internal review if needed.