Security & trust

Built for programs that cannot afford ambiguity.

Accreditation records outlive the people who create them. The platform is built so the record stays intact, access stays governed, and every action stays attributable.

Controls

What is actually in place.

Concrete mechanisms, described plainly — not a badge wall.

Workspace isolation

Every organization operates inside its own workspace. Records, documents and history are scoped to it, and nothing crosses the boundary by accident.

Invite-based onboarding

Administrators are invited by email and set their own credentials on activation. No shared passwords are ever issued or circulated.

Role-based permissions

Access is granted per module and per role, so each person reaches the surfaces their work requires and nothing beyond them.

Audit trail

Actions across registers, applications, assessments, documents and certificates are recorded with the actor and the time.

Credential handling

Passwords are stored hashed, reset flows are token-based and time-limited, and activation links are single-purpose.

Controlled provisioning

Workspaces are created by the platform team rather than self-served, so no organization exists on the platform unrecognised.

Operating practice

How we run it.

Controls are only worth what the operating practice around them is worth.

Least privilege by defaultNew users start with the permissions their role requires and are extended deliberately, not pre-emptively.
Separation between tenantsOrganization data is partitioned so that one body's assessors, cases and evidence are never visible to another.
Visibility for accountable staffQuality and operations leads can see activity across their own workspace without needing engineering support.
Clean offboardingAccess is withdrawn at the account level, while the record of what that person did remains intact for audit.

Our commitments

Plain commitments.

  • Data is processed only to operate the service you have contracted for.
  • We do not sell, rent or share customer data with third parties for marketing.
  • Access by our staff is limited to what support and operation require.
  • Security questions are answered directly — write to us and you get a real answer.
  • Enterprise agreements can include a security review and a written SLA.

Running a formal vendor assessment? Send it to corp@codeaex.com and we will complete it.

Bring your hardest questions.

Security reviews, data residency, retention, offboarding — we would rather answer it before you buy than after.

Prefer email? Write to corp@codeaex.com