Access stays under your control — down to the last sign-in

Two-factor sign-in, passkeys instead of passwords, locking to the office’s IP addresses and one device per person. All switched on from the settings — no developer needed.

Who signs in, from where and with what

Six protections the agency switches on and configures itself.

Two-factor sign-in

Besides the password — a code from an authenticator app. Without the employee’s phone the password alone isn’t enough.

Passkeys

A fingerprint, face or hardware key instead of a password. A passkey does not bypass two-factor protection.

Agency security code

The panel also asks for a shared agency code — a third layer above the password and the two-factor code.

One device each

Every profile has at most one active computer and one phone. A new sign-in kicks out the old one.

Locking to the office’s IP addresses

IPv4, IPv6 and whole ranges. From outside the panel returns “page not found”. The system won’t let you lock yourself out.

Sessions end when someone leaves

A deactivated employee loses every permission and every open session on the spot.

Where the data lives and how it is protected

Every agency is separate — with its own database and its own access.

A separate database per agency

One agency’s data doesn’t sit in a table with anyone else’s. Every site and every system has its own database.

An encrypted connection

All traffic goes through Cloudflare with full encryption to the server and mandatory HTTPS.

Documents — only after a permission check

Uploaded contracts and files don’t open from a link: the system first checks whether the person may see them.

Servers in the European Union

The agency’s data lives on servers in the EU — under the same personal-data rules the agency itself works by.

Backups on three levels

Copies are kept on the server itself, on the agency’s environment and at database level. Before every new version the system makes one more copy and can roll back.

A dedicated server on Enterprise

For a large organisation — a whole server for the agency alone, with onboarding, training and an SLA.

Personal data and GDPR

The tools are built in — the agency only chooses the periods and the wording.

Cookie consent

A consent banner using Google Consent Mode v2. Ad platform pixels fire only after consent.

Consent on forms

Enquiry forms ask for consent, and it is stored in the database together with the enquiry.

Emails — opt-in only

Marketing emails need explicit consent and carry an unsubscribe link in every email.

Deletion on a schedule

Old data can be deleted automatically after periods the agency sets.

AI assistants — no personal data

When connecting Claude, ChatGPT and others, clients’ personal data is off by default, and the assistant sees only what the employee may see.

Activity log

Who changed what, when and from which IP — kept with no time limit, visible only to people with the right.

Frequently asked questions

Can someone sign in from outside the office?

If the agency has switched on IP locking — no: for any other address the panel returns “page not found”. Other addresses or whole ranges can be allowed, for example the manager’s home.

Is there two-factor protection?

Yes — a code from an authenticator app and passkeys with a fingerprint, face or hardware key. A passkey does not bypass two-factor protection.

What happens if an employee leaves or loses their phone?

The admin deactivates the profile and all of its sessions and devices end on the spot. Without the phone the password alone isn’t enough, thanks to two-factor sign-in.

Where is the data physically stored?

On servers in the European Union. Every agency has its own separate database, and on Enterprise a whole server of its own.

How are backups kept?

Backups are kept on three levels: on the server itself, on the agency’s environment and at database level. Before every update the system makes one more copy and can roll back to it.

Does the AI assistant see clients’ personal data?

Not by default. When connecting through MCP, personal data is off, and the assistant sees only what the employee whose key it uses can see.

What is there for GDPR?

Cookie consent with Google Consent Mode v2, stored consent on forms, opt-in emails with unsubscribe, deletion of old data on a schedule and an activity log.