Security & Trust Hub

Authentication posture, sensitive-data access matrix and SIEM-ready audit log export.

Certified Signature Register
Every tamper-evident electronic signature issued in this organisation. Revoke a disputed signature or open its public verification link.
0 valid
0 revoked
Signed AtSignerDocumentContent HashStatusActions
No certified signatures match the filters

Showing 0 of 0 certified signatures. Revoking keeps the audit record but flips public verification to "Revoked".

Authentication & Trust Posture
What's enforced today and what requires platform configuration. Platform-managed items are owned by Base44's auth backend — request changes via Base44 support.
SSO / SAML 2.0
Platform-managed

Platform-managed. Request SAML federation from Base44 support to connect your IdP (Azure AD, Okta, Google Workspace).

Multi-Factor Authentication
Platform-managed

Platform-managed at login. MFA enforcement per-tenant is a platform setting — request from Base44 support.

SCIM User Provisioning
Not available

Not available. Users are invited or self-register; no automated IdP-driven provisioning yet.

IP Allowlisting
Not available

Not available at the app layer. Network-level allowlisting can be arranged via Base44 support.

Data Residency Selection
Platform-managed

Platform-managed. Confirm hosting region with Base44 support for POPIA cross-border compliance.

SIEM Audit Log Export
Available

Export the Data Access Audit log below to CSV or JSON for ingestion into your SIEM (Splunk, Sentinel, Elastic).

Sensitive-Data Access Matrix
Which role profiles can read payroll, medical, EAP, whistleblower and compensation data. Review regularly and revoke keys no longer needed.

No role profiles defined. Create role profiles in Settings to govern sensitive-data access.

Principle of least privilege: only roles that must read sensitive data to do their job should hold the key. The employee themselves always sees their own payroll/medical/compensation regardless of role.

Data Access Audit Log
Every view, export and print of a restricted record. Export to CSV or JSON for SIEM ingestion (Splunk, Microsoft Sentinel, Elastic).
WhenUserEntityRecordKeyAction
No audit entries match the filters

Showing 0 of 0 entries. Export includes all filtered rows.