Security

Access you control, and a record of every change.

Each workspace is sealed off from every other one. Admins decide how people sign in and what each role can do, and changes to records and settings are logged with who made them.

Sign-in policy Sample settings
Sign-in methods
  • Google Workspace account On
  • One-time email link On
  • Password Off
Two-step verification
Required for everyone

A second step, such as a code, at every sign-in.

Allowed domains
  • ridgeline-supply.test
  • ridgeline-mro.test

Invitations go only to these domains.

IP allowlist Enterprise
  • 203.0.113.0/24
  • 2001:db8:4f::/48

Your current network is on the list.

Session length
24 hours, renewed while in use

Isolation

Your data stays in your workspace.

Workspaces share one service, so the wall between them is built into every query and tested on every route.

  • Every row knows its workspace

    Each record, activity and setting is stored with the workspace it belongs to, and every query the service runs is limited to your workspace.

  • A query without a scope never runs

    If a query is missing its workspace scope, the service refuses to run it rather than read across workspaces.

  • Tested on every route

    Automated tests sign in to one workspace and try to read and change another workspace’s records on every route. Each attempt has to be refused, with nothing changed.

  • Live updates stay inside

    Live updates, such as a new reply or a finished call, reach only people signed in to the same workspace.

  • Its own sign-in

    Each workspace has its own sign-in organization, so signing in to one workspace never opens another you do not belong to.

Sign-in

Admins decide how people get in.

Set one policy for the whole workspace. It applies to everyone, admins included.

  • Choose the ways in

    Accept Google Workspace accounts on your domains, a one-time link by email, a password, or any mix of the three.

  • Two-step verification

    Leave it optional or require it for everyone. When it is required, people finish a second step, such as a code, every time they sign in.

  • Allowed domains

    List up to 20 company domains. Invitations then go only to those domains, and you can let people there join on their own with a role you pick.

  • Sessions that end

    A session lasts 24 hours and renews while someone keeps working. Anyone can sign out everywhere from their profile, and admins can do it for anyone.

  • Deactivate in one step

    Deactivating someone ends their sign-in everywhere and frees their seat. You choose who takes over their work, and you can reactivate them later.

  • IP allowlist, on Enterprise

    Name the networks people may sign in and work from, as IPv4 or IPv6 ranges. Every request is checked, and a list that would block your own network is refused.

Roles

Three roles, checked on every request.

Everyone has one of three built-in roles. The service checks the role on every request, so a hidden button is never the only guard.

  • Admin

    Everything, including the team, phone lines, settings and data tools.

  • Rep

    Works leads: calls, email, tasks and opportunities.

  • Viewer

    Reads records and reports. Changes nothing.

  • Custom roles, on Enterprise

    Start from a built-in role and take away what a group should not do, such as exporting data or deleting records. A custom role can narrow a role, never widen it.

Audit

A record of who changed what.

Changes to records and settings are written to your workspace’s audit log as they happen.

  • Every change, with its author

    Changes to records and settings go through one write path that logs who made each change and what it was before and after.

  • Reasons on the record

    Some actions, such as removing a do-not-contact suppression or block, ask for a reason, and the reason is kept in the log.

  • Export the log, on Enterprise

    Download the audit log for the dates you choose, as CSV for a spreadsheet or JSONL for your own tools.

  • Support access you can see

    If our support team needs to see what you see, they open a read-only session with a stated reason, and it ends on its own within 30 minutes. Your audit log records who opened it, why and when it ends, and each request during the session is logged.

Your data

Take all of it with you, any time.

  • A full export on every plan

    Admins can export the whole workspace at any time: every record, activity and setting in one compressed JSONL file, with each line labeled by its table. Download links last 7 days.

  • Mail access stays sealed

    The token that connects your Gmail is encrypted before it is stored and is never included in an export. The workspace never sees your Google password, and disconnecting a mailbox deletes its token.

  • History outlives the team list

    When someone leaves the team, their calls, emails, notes and audit entries keep their name.

Protection

One do-not-contact list, checked everywhere.

Opt-outs, bounces and manual suppressions land on one list, and every call and email is checked against it.

  • Suppress an address, a domain or a number

    Add an email address, a whole domain or a phone number. Opt-outs and bounces are added on their own.

  • Checked before every call and send

    The same check runs before every call and every email, and again the moment a scheduled email goes out.

  • Block a whole account

    Blocking an account cancels its open team tasks and, where work was open, opens a review for admins. Email already queued to it is stopped by the check at send time.

  • Look up any contact

    Admins can run an address or number through the same check. Lookups are rate limited, and each one is audited with the value hashed.

AI safeguards

AI drafts wait for a person.

AI drafting stays off until an admin turns it on. When it is on, every draft works from your records and needs approval.

  • Grounded. Each draft lists the facts it drew on from the record.
  • Checked. A second model checks each sentence against those facts. The check is on by default.
  • Approved. The server will not send an AI draft nobody approved.
How AI drafting works

Found a security issue?

Tell us what you found and how to reproduce it. Questions for a security review go to the same address.

support@lumina-erp.com

Put protection in place before the first call.

14 days free 3 seats No card to start