Security, in plain English.
Trigway holds your clients' compliance records, so it needs to be hard to get into and easy to check. Here is how it works, in words you can repeat to a client.
A password is never enough on its own.
Everyone signs in with a passkey, the same face or fingerprint check that unlocks their phone, or with a code from an authenticator app.
We don't send sign-in codes by email. If someone gets into a mailbox, they still can't get into the portal.
Every client is walled off, in the database itself.
Hiding another client's data on screen isn't enough. Each client's records are separated at the database level, so a request made for one client only ever reaches that client's data.
Your team works across every client. Each client sees only their own.
Nobody looks in without the client knowing.
When your team opens a client's portal, the client sees a banner while it's happening and a record afterwards: who, why, for how long, and what changed.
Sessions are read-only by default. Keys, tokens and other secrets stay hidden from support staff throughout.
Every sensitive action, written down.
Sign-ins, permission changes, support sessions, signatures and exports are all logged with who, what and when. Clients can see every entry that concerns them.
Trigway is pre-launch. We'll publish hosting details and any independent testing on this page once they're confirmed, not before. If you have questions now, ask us when you join early access.