Skip to content

Security and data protection

Docordia and SAFEFLOW are designed along ISO guidelines so your data is auditable and governed by the permissions you set. This page lists what the systems do today.

Four permission layers (Docordia)

Permissions are re-checked on the server every time, not just hidden in the interface.

  • User roles
  • Permission groups such as CAPA approvers or the MRB
  • Per-cabinet and per-document-type permissions
  • Contextual permissions

A usage log that cannot be edited

Important actions are always recorded, and there is no button to edit or delete the log.

  • Document views, downloads and prints (Docordia)
  • Approver, time and reason for every approval
  • PDF watermarks on download and print (Docordia)

SAFEFLOW hash chain

Every permit change is recorded append-only and chained with SHA-256 hashes.

  • Integrity check for the whole chain
  • Permit PDFs carry a verification QR code
  • Status transitions locked in both the application and the database

PDPA

Docordia includes tools that help you comply with Thailand’s Personal Data Protection Act. SAFEFLOW is designed to support PDPA compliance, with you as the data controller.

  • Consent records
  • A queue for data-subject requests
  • Retention and disposal rules
  • Legal hold on disposal when the law requires it

SaaS or on-premise

You choose where the data lives.

  • Both Docordia and SAFEFLOW can run on your own servers
  • On-premise, your IT team controls the servers and backups
  • Docordia SaaS packages are in development

Backups and web application protection

Basic measures that have been tested.

  • A backup procedure with a rehearsed restore (Docordia)
  • Security headers, rate limiting and CSRF protection
  • Passwords stored with one-way hashing

Standards we design along

ISO certification belongs to the organisation audited by a certification body; the software helps prepare the documents and evidence auditors ask for.

  • Docordia is designed along ISO 9001 and ISO/IEC 27001 guidelines
  • SAFEFLOW is designed to support ISO 45001 clause 8.1

Want to go through the details with your IT team?

We can answer security questionnaires and meet your IT team or data protection officer (DPO).

Contact us