Security

Your company is a tenant — not a shared inbox.

Prism is multi-tenant. After sign-in, every query is scoped to that company. We do not ask the app to “pick a tenant” for authorization.

Session-scoped tenant

The signed token carries tenant context. Protected APIs reject requests that lack it.

Role gates

Engineer, admin, and finance see different consoles. Superadmin is reserved for platform tenant management.

Engineer sessions

A field login is one active session. A new device replaces the previous one. Admins can force logout.

Admin and finance sessions

Web roles may keep more than one session so HQ is not locked to a single browser.

Branded, not leaked

Emails and PDFs render that tenant’s company profile. Another tenant’s machines and claims are not on the same screen.

Channels you configure

WhatsApp number, mail sender, and intake QR destination are set per tenant — optional, not assumed.

Workflow

  1. 01

    User signs in with company credentials

  2. 02

    Session establishes tenant and role

  3. 03

    Mobile and console only load that tenant’s records

  4. 04

    Output (mail, PDF, quotes) uses that tenant’s brand

Prism does not publish SOC, ISO, or HIPAA badges on this site because those certifications are not claimed in the product.

Request a demo