Role-Based Access Control

  • Access scoped by role, not shared logins
  • SuperUser controls separated from day-to-day Admin permissions
  • Applies consistently across every connected plugin

Audit Logging

  • Administrative and access activity recorded, not just application errors
  • Supports internal governance reviews and customer assurance conversations

Optional Multi-Factor Authentication

  • TOTP-based MFA available for user accounts
  • Configurable to fit your organisation's authentication policy

Encrypted Secrets

  • Plugin credentials and connection secrets encrypted at rest
  • Backups encrypted before they leave the environment

Cloudflare Access Support

  • Perimeter access control support for zero-trust network setups
  • Sits alongside real-IP rate-limiting for exposed endpoints

Data Sovereignty by Design

  • Single-tenant per customer — never a shared multi-tenant data store
  • Customer-hosted deployment keeps data inside your own environment entirely
  • See Deployment Options for SaaS vs. customer-hosted detail

AI With PII Masking Built In

  • Bring your own AI: the assistant runs on an AI provider account you control — your Anthropic or OpenAI API key, or Amazon Bedrock in your own AWS account on self-hosted deployments. Your data goes only to that provider, under your terms, and none of them use API data for model training by default
  • Personal data is masked before anything reaches the model: names and emails become stable pseudonyms, and payment cards, bank details, government IDs and leaked credentials are always redacted — no setting overrides that
  • Optional strict PII mode (self-hosted Bedrock deployments) adds entity-level detection — names and addresses inside free text — via Bedrock Guardrails
  • AI question logs are encrypted at rest with 30-day retention; nothing leaves a customer-hosted instance unless an admin opts in

Designed to Support Enterprise Deployment Models

Insights is built with the controls enterprise security and compliance teams expect to see — RBAC, audit logging, MFA and encryption — as standard, self-hosted deployment. We don't claim formal certifications such as SOC 2 or ISO 27001; we're direct about that so your own compliance assessment starts from an accurate baseline.

Talk Through Your Security Requirements

Whether it's a specific control, a self-hosted deployment, or how Insights fits your existing compliance programme, we'll walk through it directly.


Security or compliance questions? Contact us at sales@insights-online.com