Bank-Grade Protection & Multi-Tenant Barriers

Architected for Absolute Data Privacy & Zero-Trust Reliability

Learn how Bizgy guarantees strict tenant database isolation, impenetrable local two-factor authentication, active device session control, and granular role enforcement.

Multi-Tenant Isolation Barrier

Every tenant is issued a dedicated integer code (e.g. 1001, 1002) stamped on every query. Global Eloquent scopes enforce automatic tenant separation so data leaks between companies are mathematically impossible.

WHERE company_id = ? AND ...

Air-Gapped Local 2FA Engine

Two-Factor Authentication is generated on-premises via local SVG rendering. Authenticator keys never touch external third-party cloud APIs (like Google Charts), safeguarding against credential sniffing.

BaconQrCode Zero-External Dependency

Live Device Tracking & Kill-Switch

Monitor all active user sessions across laptops, desktops, and mobile devices in real time. Terminate compromised or forgotten remote sessions with a single click.

Immediate Token & Cookie Revocation

Granular Permission Matrix

Roles and permissions are governed at the atomic action level (`view`, `create`, `edit`, `delete`, `approve`, `export`). Cached in memory for sub-millisecond route authorization.

Spatie RBAC with Company Scoping

High-Speed Multi-Tier Caching

Three-level caching (Global platform, Company subscription, User permissions) prevents database bottlenecks during peak attendance punch-in spikes while securing sensitive data.

Automated Invalidation on Role Change

Audit Logs & Data Protection

Every attendance punch, manual override, salary modification, and user permission modification is timestamped and attributed with full traceability for compliance.

Comprehensive Immutable Event Log

How Tenant Isolation Works Under the Hood

Bizgy uses defense-in-depth isolation across three synchronized software tiers.

01. Request Layer

Tenant Context Middleware

Every incoming HTTP request resolves the authenticated user's active company binding. If a user attempts to forge a request targeting another company's resource ID, the middleware immediately aborts with a 403 Forbidden.

02. Query Scope Layer

Automatic Model Scoping

Eloquent models (`Employee`, `Attendance`, `Role`, `Department`) enforce an internal tenant scope. Even developers writing raw repository queries cannot accidentally pull cross-company data.

03. Storage & Export Layer

Namespaced File Quarantine

Uploaded company logos, employee KYC documents, salary slips, and attendance biometric exports are stored in company-segregated directory structures with signed temporary URL downloads.

Frequently Asked Security Questions

No. Every database query executed in Bizgy explicitly requires the company tenant ID. Cross-tenant access is physically barred by application-wide query scopes and verified by our automated test suite.
Company admins have the flexibility to enforce Two-Factor Authentication either globally across all staff or specifically for finance, HR managers, and administrative roles.
Yes. Under our Enterprise tier, we provide isolated private cluster deployments or on-premises Docker containers for enterprises with strict data residency mandates.

Ready to Run on a Secure, Modern ERP?

Spin up your organization with self-service registration in 60 seconds. Instant tenant provisioning and full 14-day access.