Security & Governance

Controls your auditors expect, built into the platform

Security in Yess ERP is enforced at the database layer, not just the interface — so access rules hold no matter how the data is requested.

Row-level data isolation

Every table enforces database-level policies, so a user can only read rows their role and company allow.

Granular role permissions

Custom roles define module-by-module access. Server endpoints re-verify permission and reject unauthorised calls.

Immutable audit trail

Creates, edits and deletes are captured with before/after values, actor and timestamp — exportable to CSV and PDF.

Separation of duties

Approval workflows and delegation rules keep initiation, approval and posting in different hands.

Encrypted transport & storage

All traffic runs over TLS and data at rest is encrypted by the managed cloud platform.

Backups & recovery

Automated daily backups with point-in-time restore on business and enterprise plans.

Session & access visibility

Administrators can review active users, disable accounts instantly and track privileged actions.

Secure authentication

Email verification, password strength enforcement, password reset and optional social sign-in.

Operating practices

We keep the platform defensible day to day, not only at launch.

  • Least-privilege defaults for every new role
  • Server-side validation on all write operations
  • Regular automated security scanning of the database
  • Segregated environments for preview and production
  • No shared administrator accounts
  • Documented data retention and export on request