Security
Controls, described plainly.
This page lists the controls built into SANQOR today. It does not claim certifications SANQOR does not hold.
Data isolation
One client's records must never be visible to another.
- Row-level security on tenant data
- Tenant-scoped data access
- Super admin controls kept separate
Access control
People see and change only what their role allows.
- Role-based permissions
- Invite-first onboarding
- No open tenant discovery
Auditability
What happened, and who did it, must be answerable later.
- Sensitive actions logged
- Watchlist import history
- Email delivery logs
- API request logs
API security
Machine access needs the same discipline as people.
- Hashed API keys
- Only key prefixes are visible
- Revocation
- Request logging
List monitoring
Screening results depend on current data.
- Watchlist import status
- Freshness warnings
- Failed import visibility
Email safeguards
Invitations are an access path and are treated as one.
- Environment-aware sender domains
- Invite token safety
- Delivery tracking
Evidence retention works alongside these controls. Decisions, notes and attachments stay with their case, and case packs can be exported when a review asks for them.