Security

Trust built into the execution backbone.

Nodetra handles sensitive work data, documents, approvals, files, and people records. The security story is structural: tenant isolation, access control, auditability, and compliance.

Tenant boundary Data stays inside the workspace context
Identity MFA / OAuth / sessions
Access RBAC and feature permissions
Knowledge Denied unless explicitly granted
Audit Every sensitive action is recorded
Audit stream

permission.updated

docs.share.created

tenant.context.verified

Trust posture

Specific controls beat generic badges.

Isolation

Tenant boundaries

Row-Level Security and session tenant context protect organization data at the database layer.

Access

Role-based control

Admin, manager, user, department, and feature capabilities keep surfaces scoped.

Docs security

Permission-aware knowledge

Private pages, mentions, search results, and shares default to deny.

Identity

Authentication controls

JWT sessions, refresh behavior, Google OAuth, and 2FA support the login model.

Audit

Know what changed

Security events and important user actions can be reviewed and exported.

Compliance

KVKK and GDPR posture

Privacy and retention concerns are tied to actual product controls, not generic claims.

AI governance

AI actions stay inside the same security model.

Context

Permission-bound answers

AI responses use the tasks, docs, projects, meetings, and reports the current user is allowed to access.

Approval

Writes wait for review

Create and update actions are proposed through approval cards before they change workspace records.

Models

Provider and model controls

Admins can manage provider consent, model availability, premium grants, and usage policy.

Audit

Consent and activity trail

User consent, provider settings, quality signals, and AI action history stay inspectable.

RLSDatabase-level tenant boundaries
2FASecond-factor authentication support
AuditActivity trails for sensitive actions
Fail closedPrivate docs and mentions avoid label leaks