Data Encryption
All data at rest is encrypted with AES-256. All data in transit uses TLS 1.3. MIRA's vector memory (Qdrant) stores no PII — only pattern data. Your facility records remain in your database environment.
FacilityFlow is built for enterprise environments that have real data governance requirements — regulated industries, public sector organisations, and multi-national portfolios where data sovereignty isn't optional. Every MIRA action is logged, encrypted, and auditable.
Our security and data governance pillars.
All data at rest is encrypted with AES-256. All data in transit uses TLS 1.3. MIRA's vector memory (Qdrant) stores no PII — only pattern data. Your facility records remain in your database environment.
12+ predefined roles with granular field-level permissions. Role-based UI — technicians see work orders; executives see KPIs; compliance officers see permits. Configurable per-customer, per-site, and per-module.
Two-factor authentication (2FA) enforced for all user accounts. Single Sign-On (SSO) via OAuth 2.0, SAML 2.0, Azure AD, and Okta. API key management with configurable rate limiting.
Every action — user and MIRA — is logged with timestamp, user ID, IP address, and change context. Full audit trail searchable and exportable at any time. Login attempts logged and anomalies flagged.
Every MIRA decision includes: the evidence she used, her confidence score, the action she took (or recommended), and the real outcome. AI actions are not a black box — they are the most auditable part of the platform.
Cloud-hosted with enterprise-grade infrastructure, or on-premise deployment in your own environment. Multi-company and multi-tenancy support. Your data never commingled with other customers' data.
Audited standards and configurations.
| Framework | Status |
|---|---|
| SOC 2 Type II | Certified. Report available on request under NDA. |
| GDPR | Compliant. Data processing agreements available. |
| ISO 27001 | Aligned. Certification in progress. |
| AES-256 + TLS 1.3 | Standard encryption across all data, at rest and in transit. |
| RBAC (12+ roles) | Granular access control across every module and record type |
| On-premise deployment | Full data sovereignty for regulated environments |
FacilityFlow's HSE module is one of the deepest in the market, built for regulated and high-risk environments where compliance failures have legal and safety consequences.
| HSE Capability | What It Delivers |
|---|---|
| Permit to Work (PTW) | Digital PTW with hazard identification, isolation points, gas tests, PPE, and signatures |
| LOTO (Lockout/Tagout) | Full LOTO transaction management with photographic evidence and digital sign-off |
| MSRA (Method Statement & Risk Assessment) | Structured MSRA workflow with team members, hazards, controls, and notifications |
| Incident Investigation | Safety incident logging, witness records, RCA, corrective actions, and follow-up tracking |
| Safety Inspections | Checklist-driven inspections with corrective action tracking |
| Compliance Calendar | All regulatory obligations tracked with deadline alerts — 47 daily checks via MIRA |
| Certifications | Organisational and employee certifications tracked with renewal reminders |
| Safety Audit Trail | Every safety action logged, signed, and searchable |
Enterprise and regulated-industry customers often have bespoke requirements — on-premise deployment, custom data residency, specific compliance frameworks, or enhanced audit capabilities. Our security team works with IT, legal, and compliance teams to address your specific requirements before you sign.