SECURITY

Access to the work.
Not to everything.

Ingsera follows least-privilege principles: every user, service and interface receives only the access required for its purpose.

✓
Public layer protectedHTTPS · isolated runtime · protected API · browser security policies
01

Isolated service

The public website runs separately from the core SpecFlow services and has no direct database connection.

02

Role-based access

Identity and permission are separate checks. Workspace users only see approved projects and actions.

03

Protected transport

HTTPS and browser security policies protect public traffic and restrict unsafe third-party content.

04

Least privilege

The Ingsera service runs under a dedicated system account with access limited to its own directories.

05

Primary and backup storage

Operational data stays on Ingsera-owned servers. Google Drive or Yandex Disk can be used only for encrypted backup copies.

06

Phone verification

Access is confirmed by a call to a Russian mobile number assigned by an administrator.

IMPORTANT

The demo contains no operational data

Projects, people and documents shown in the demo are fictional. Real sources will be connected through a separate protected API after authentication and roles are configured.