Security

Security controls that match operational accountability

Equipment records can reveal people, locations and safety decisions. LiftKept’s architecture treats tenant scope, permissions and immutable history as product behaviour—not optional administration settings.

  • Tenant scope by default
  • Role and location-aware access
  • Security-relevant activity recorded

Data boundaries

Every request is scoped to the customer and authorised location

Organisation boundaries apply to application queries, exports, background work and support operations. Customer settings cannot weaken tenant isolation.

  • Tenant-aware data access
  • Site and loft scope
  • Isolation tests in the release gate

Identity

Privileged access receives stronger controls

The commercial release is designed for MFA on privileged roles, expiring contractor access and security logging around authentication and administration.

  • No shared user identities
  • Recoverable administrator safeguards
  • Just-in-time, logged platform support

Integrity

History is corrected, never silently rewritten

Custody-changing actions identify an actor and create immutable events. Corrections link to the original record and preserve the reason for review.

  • Append-only operational events
  • Separate administration history
  • Scoped, period-defined export

Next step

See LiftKept against your own operation

Bring a small slice of your equipment register. We will map one real movement, one exception and the evidence your team needs to retain.

Email try@liftkept.com