Skip to content

Security

Your client data, kept to your company

Cordyn holds site details, access instructions, contract terms and client relationships. That information is treated as sensitive by default, and separation between companies is enforced in the software rather than in the interface.

  • A dedicated environment per company

    Your company signs in at its own address — companyname.cordynhq.com. Sessions are bound to that address and are not accepted anywhere else, so a session issued for one company cannot be presented at another.

  • Isolation enforced on the server

    Every query is scoped to your company on the server, in the query itself. Isolation is never a matter of hiding records in the interface. A request for a record belonging to another company returns nothing at all.

  • Role-based access

    71 permissions across 13 roles, editable per company, so a dispatcher, an account manager and a finance lead each see the part of the account that belongs to them. Client portal users are held to a separate allowlist entirely.

  • Authentication

    Passwords are hashed with scrypt. Sessions are server-side and revocable, and only a hash of the session token is stored, so a database read cannot be replayed as a sign-in. Time-based two-factor authentication is available for staff accounts.

  • Audit trail

    An append-only record of authentication, approvals, price changes, portal access grants, role changes and every state transition on a commercial record — with the actor, the address and the time.

  • Approval integrity

    An approval is bound to the exact content it approved. Change the pricing afterwards and the approval no longer stands, so a signed-off proposal cannot be quietly edited after the fact.

Controls

Applied on every request

Transport
HTTPS only, with HSTS. Strict content security policy, clickjacking and MIME-sniffing protections on every response.
Request integrity
Cross-site request forgery protection on every state-changing request.
Abuse resistance
Rate limits on sign-in, password changes, uploads and portal submissions. Sign-in responses do not reveal whether an account exists.
Uploads
Documents are checked against a file-type allowlist and always served as downloads, so an uploaded file cannot execute against a live session.
Storage
Per-company storage allocation with quotas, held outside the application directory.
Data separation
Client portal users receive an allowlisted subset of information. Internal notes, costs and margin are never exposed to them.

Straight answers

Certifications and assurance

Cordyn does not currently hold SOC 2, ISO 27001 or any comparable third-party certification, and we will not claim otherwise. The controls described on this page are implemented and testable today.

If your procurement process requires a security review, questionnaire or a discussion of our roadmap toward formal certification, contact us and we will answer directly.

Verification

Tested, not asserted

The isolation and access boundaries above are covered by an automated test suite that runs against a real database on every change. Those tests attack the boundary deliberately: they attempt cross-company reads using genuine identifiers from a second company, and they confirm that a client portal user cannot obtain internal permissions even if a role were misconfigured.

  • Cross-company access attempts return nothing, not a permission error
  • Portal users are filtered against an allowlist independently of their roles
  • Sessions are rejected on any address other than their own company’s

Bring your security questions to the demo

We would rather answer them before you buy than after.