Security & privacy
TomIT is built with privacy and security first — workspace isolation, encryption, audit trails and GDPR-friendly hosting, out of the box.
Everything runs on EU infrastructure under EU rules (GDPR). Your data stays in the EU and is never used to train public models or shared with other workspaces.
Every workspace is isolated at the database level — there is no way for one workspace to see another's data, and every query is scoped automatically.
All traffic is TLS-encrypted. Sensitive credentials (SMTP, integration keys) are encrypted at rest with AES-256-GCM, and nightly backups are GPG-encrypted.
Owner, superadmin, admin, KB admin, user and agent roles — each with a strictly scoped view. Users only see assets assigned to them.
Every change to an asset is recorded with the old and new values, who did it, and when — by people or by agents. Sensitive actions land in a separate admin audit.
Encrypted backups run every night and are kept on the server. The demo workspace is reset nightly so you can explore freely.
Export your data to CSV, Excel or PDF any time. If you leave, your data goes with you — no lock-in.
Login sessions are HttpOnly, SameSite cookies with revocation on password change or logout. API access is key-based and audited.
Workspaces, fully isolated
Every workspace gets its own fully isolated data scope. A user in one workspace can never read, search or export another workspace's devices, contracts or users — verified continuously, not just promised.
Security at a glance
Start free and check the audit trail, the isolation and the exports yourself.