Trust center

Security at Ecosys One

Security is designed around tenant separation, least privilege, recoverable workflows, and clear reporting, not unsupported certification claims.

Effective August 31, 2026

Application and data controls

Organization and workspace membership, specialized finance and payroll roles, client-contact permissions, and private accountability ownership are enforced at the application and database layers. Anonymous database access to operational tables is revoked; privileged server operations use secrets that are not exposed to the browser.

Authentication and integrations

Authentication is provided through Supabase Auth. Connected providers use OAuth consent rather than collecting provider passwords. Refresh and access tokens are stored through encrypted database secret storage, and webhook endpoints validate provider signatures where supported.

Operational safeguards

Release checks include type validation, linting, production compilation, static accessibility checks, database security advisors, and workflow testing. Audit records are retained for sensitive workflows such as signatures, billing events, permission changes, and provider synchronization.

Customer responsibilities

Customers should require strong unique passwords, enable available multi-factor authentication, promptly remove former members, grant the narrowest practical roles, review connected-app consent, protect downloaded exports, and report suspicious activity.

Responsible disclosure

If you believe you found a vulnerability, do not access or alter another person's data. Send a description, affected URL, reproduction steps, and non-sensitive evidence to support@impctrsmgmtgroup.com. We will acknowledge a credible report and coordinate remediation. Do not include credentials, access tokens, or private customer content in ordinary email.

No third-party security certification is claimed on this page. Material certifications will be listed only after they are independently completed.