Security
Security posture
Visitor and access data is sensitive by default. IVMS is built with that assumption from the infrastructure up — not retrofitted after a breach.
Access control
- SSH restricted to IAP tunnel only
- Database reachable over loopback only
- Role-based access per user
Authentication
- Multi-factor authentication with recovery codes
- Rotating/refreshable login sessions
Monitoring & testing
- Full audit log of every action
- Scheduled dynamic application security testing (DAST)
Data protection
- TLS everywhere in transit
- Per-tenant data isolation
- Allowed-IP restrictions for gate/kiosk terminals
Ready to retire the paper register?
Book a live demo — we'll walk through check-in, approvals, and reporting with your own gates and roles.