Security

Data protection built into the architecture

Security is not a feature added later. E-OFIS was built as a multi-organisation system from the start, and every request is checked for who is making it, from which organisation and with what rights.

Fully isolated organisations

Every record is tied to an organisation. The system won’t let anyone open another organisation’s data even through a direct link — and this is verified by automated tests.

Roles and permissions

Roles are assigned within an organisation. Every page and action is protected by its own permission; owner and administrator roles can only be assigned by the system administrator.

Access log

Every successful and failed login is recorded with its time, IP address and device.

Secure connection

HTTPS, HSTS and security headers (CSP, X-Frame-Options and more). Login attempts are rate-limited.

Telegram authentication

Mini App data is verified with Telegram’s signature; employees can only access the account linked to them.

Backup and recovery

Regular backups. A deleted file first goes to “Deleted items” and can be restored during the recovery period.

Security

The principles we follow

  • Your data is only for you and your employees — we don’t sell it or use it for advertising.
  • AI insights are generated inside the system; data is not sent to third-party AI services.
  • Each employee sees only the data their role requires.
  • When an employee leaves, their access is closed immediately and their history is kept.

See how it works for your organisation in 30 minutes

In the demo we show the system on your own structure and answer your questions. No obligation.

  • Nothing to install
  • We set up your structure together
  • We connect the Telegram bot for you