Security

Security posture

Visitor and access data is sensitive by default. IVMS is built with that assumption from the infrastructure up — not retrofitted after a breach.

Access control

  • SSH restricted to IAP tunnel only
  • Database reachable over loopback only
  • Role-based access per user

Authentication

  • Multi-factor authentication with recovery codes
  • Rotating/refreshable login sessions

Monitoring & testing

  • Full audit log of every action
  • Scheduled dynamic application security testing (DAST)

Data protection

  • TLS everywhere in transit
  • Per-tenant data isolation
  • Allowed-IP restrictions for gate/kiosk terminals

Ready to retire the paper register?

Book a live demo — we'll walk through check-in, approvals, and reporting with your own gates and roles.