Security

Security, in plain English.

Trigway holds your clients' compliance records, so it needs to be hard to get into and easy to check. Here is how it works, in words you can repeat to a client.

01 · Sign-in

A password is never enough on its own.

Everyone signs in with a passkey, the same face or fingerprint check that unlocks their phone, or with a code from an authenticator app.

We don't send sign-in codes by email. If someone gets into a mailbox, they still can't get into the portal.

HC
Sign in to Harbour CyberUse the passkey on this device.
Passkey Allowed
Authenticator app Allowed
Password on its own Not allowed
Code sent by email Not allowed
02 · Client isolation

Every client is walled off, in the database itself.

Hiding another client's data on screen isn't enough. Each client's records are separated at the database level, so a request made for one client only ever reaches that client's data.

Your team works across every client. Each client sees only their own.

Your team Works across all clients
Kestrel Logistics
Devices41
Evidence64
Agreements3
tenant · kestrel
Marsh and Vale
Devices18
Evidence37
Agreements2
tenant · marshvale
Oakmoor Dental
Devices9
Evidence22
Agreements1
tenant · oakmoor
A request from Kestrel Logistics can only reach rows tagged with Kestrel's tenant reference.
03 · Support sessions

Nobody looks in without the client knowing.

When your team opens a client's portal, the client sees a banner while it's happening and a record afterwards: who, why, for how long, and what changed.

Sessions are read-only by default. Keys, tokens and other secrets stay hidden from support staff throughout.

Alex Payne from Harbour Cyber is viewing your portal. Read-only support session. Nothing can be changed. Ends at 14:30.
Hidden in support sessionsSecrets never render while a platform engineer is in your account.
WhoAlex Payne
WhyMissed updates
How long14:02 to 14:30
ChangedNothing
04 · Audit log

Every sensitive action, written down.

Sign-ins, permission changes, support sessions, signatures and exports are all logged with who, what and when. Clients can see every entry that concerns them.

Audit log6
TimeWhoActionReference
14:30Alex PayneEnded support sessionSES-2026-10-07-3f2a
14:11Alex PayneSecret request blocked in support sessionSES-2026-10-07-3f2a
14:02Alex PayneStarted read-only support sessionSES-2026-10-07-3f2a
11:47Sam MorleySigned 2027 managed security agreementAGR-2027-014
10:15Sam MorleyRemoved admin access for a former employeeUSR-a91e
09:12Sam MorleySigned in with a passkeyAUTH-77c0
Kestrel Logistics · Showing today
What's not here yet

Trigway is pre-launch. We'll publish hosting details and any independent testing on this page once they're confirmed, not before. If you have questions now, ask us when you join early access.

Early access

Be one of the first MSPs to run on Trigway.

We're opening Trigway to a small group of providers before launch. Tell us about your clients and your tools, and we'll be in touch.