PunchLink PunchLink
๐Ÿ›ก Security & Compliance

Your data remains your data

EU hosting, encryption, GDPR, audit trail, industrial compliance. Everything your IT Director needs to know, clearly explained.

5 pillars of PunchLink security

๐Ÿ” Identity

Strict authentication, bcrypt hashed passwords in database, Microsoft/Okta SSO optional (Enterprise included).

๐Ÿ›ก Multi-tenant scope

Postgres RLS: each user sees only projects they are an active member of. No cross-tenant access possible.

๐Ÿ‘ค Business roles

7 native roles (DO, AMO, CDP, Procurement, Contractor, Sub-contractor, Third-party, HSE). Read/write/validation filtered by role.

๐Ÿ“‹ Audit traceability

Every action recorded (who, what, when, result). Exports for internal compliance and external audits.

๐Ÿšจ Control

Kill-switch L2V (security incident), 1-click revocation by user, per-user disable by admin. 3-level control.

๐Ÿค– PunchLink AI Security

Revocable Bearer token, bcrypt hash, dedicated audit trail. See AI security page โ†’

Hosting and compliance

Enterprise Plan โ€” Enhanced Security

Discuss with your IT Director PunchLink AI Security โ†’
Frozen justification list PunchLink with SHA-256 cryptographic proof: reference PL-FROZEN-2026-000005, to keep minimum 10 years

Cryptographic proof โ€” compliance argument

An immutable snapshot of open reserves and active retentions at point in time, sealed by SHA-256 hash. Document with evidentiary value, 10-year retention, legally enforceable. The contracting authority freezes a reference state before each critical milestone โ€” not a dated Excel copy.

PunchLink project configuration with AI and Intelligent DOE killswitches disableable per-project for ITAR clients or classified contracts

AI killswitches for sensitive clients

ITAR data, classified contracts, defense, personal data: disable generic AI and intelligent DOE at project level, without giving up the platform. EU-exclusive hosting (Supabase eu-west-1), no data transfer outside EU for your client data. Native GDPR compliance.