Each organisation, kept apart by the database
Every table that holds your data carries your organisation, region and owner, and PostgreSQL row-level security checks them on every query. A query that forgot a filter returns nothing — not someone else’s invoices. The application connects as a role that cannot switch those checks off.
Regions are a boundary too
Regional managers and reviewers see the regions they belong to. Inside a region, reviewers can be limited to their own work. Administrators decide, and the database enforces it.
Sign-in
Passwords hashed with Argon2 and checked against known breaches; short-lived sessions that rotate, end on every device when a password changes, and lock out repeated guessing. Google, Microsoft and your company’s own single sign-on (OpenID Connect), which you can make mandatory.
Roles, permissions and approvals
Four roles, adjustable per person. Sensitive changes — people, roles, organisation settings — can wait for a second person’s approval, with the reason recorded.
An audit log that answers “who did that?”
Sign-ins, changes, exports, invitations and every request that left for the AI assistant are recorded with who, when and from where. Administrators can read and export it.
AI only if you say so
The assistant is off until your administrator turns it on. Names, invoice numbers and amounts are replaced by placeholders before anything is sent, reading whole documents is a separate switch, and your data is never used to train models.
Backups you can count on
An encrypted copy of the database and every file leaves the server every night; the provider only ever holds ciphertext. Every week a backup is restored and checked automatically.
Hosting
PineMetric runs in the European Union (Germany). Traffic is HTTPS-only with HSTS, security headers and a strict content policy; servers take security updates automatically.