Security you'd build if you had a year to spare.
Two-factor auth, login alerts, suspicious-login detection, RBAC, IP whitelisting, encrypted secrets, CSRF protection, rate limiting, full audit logs — done right, by default.
Everything Security ships with — out of the box.
No add-ons. No upsells. The features below are all included on day one of your 14-day trial.
Authenticator app pairing, recovery codes, enforceable per role. Live in production.
Passwordless or as a 2FA channel. 6-digit, 5-minute expiry, single-use.
Owner / admin / staff roles. Per-product on/off — admin can disable Sign for a tenant.
Every mutation across CRM, Bigin, Sign, SalesIQ, Forms, Bookings, Survey, Workflows, Invoicing — captured with IP + UA + geo.
Different country, new device, brute-force pattern → admin gets pinged. Login_history collection.
Restrict admin login to allow-listed IPs. Per-tenant, configurable.
Passwords hashed with bcrypt (12 rounds). Sessions are 7-day JWTs, rotated on password change.
OTP / login / public form / contact / AI endpoints all rate-limited. Redis-backed in production, in-memory fallback.
All traffic 256-bit TLS. Browsers blocked from CSRF via SameSite + token validation.
