Security approach

Operational trust, built into the data model.

NeatRound is engineered as a multi-tenant SaaS where service proof, customer records, and invoice-ready facts cannot depend on a hidden button or a hopeful convention.

Current foundation

Controls already shaping the build.

These are engineering controls, not claims of certification. Formal compliance claims will only appear after independent evidence and approval.

Tenant isolation in the database

Tenant-bearing product tables force row-level security, use explicit grants, and are tested against wrong-tenant access.

Deny by default

Identity alone is not access. Current membership, named permission, assignment, tenant state, and workflow state are checked at execution.

Integrity before convenience

Composite foreign keys, uniqueness, versions, transactions, idempotency keys, and row locks protect service and billing facts.

Internal schemas stay internal

The Data API exposes only the application schema. Privileged helpers, jobs, and audit storage are kept outside the client API.

Less sensitive data in telemetry

Logs and audit metadata exclude service notes, proof content, addresses, access instructions, credentials, and raw form bodies.

Adversarial release gates

Database security tests, dependency audits, browser checks, schema linting, and explicit threat-model review run before promotion.

Before public beta

Independent testing and a clear disclosure path.

The launch gate includes restore testing, central observability, incident contacts, privacy/legal review, and a published vulnerability-reporting process.

Start 7-day free trial