Skip to content
Private beta: secure, managed business workflows for selected small teams.

Security and privacy

Give every person the access they need—and no more than they need.

Thorn Business Platform is designed around tenant boundaries, role-aware access, secure sessions, and managed environments so teams can evaluate a connected platform with clearer control over business information.

Image: Unsplash

Security and privacy

Give people the access they need without exposing everything else.

Thorn Business Platform combines authenticated access, tenant separation, roles, permissions, and record responsibility so access can reflect how a team actually works.

Use important data deliberately

Use representative or non-critical data unless data handling, backups, retention, recovery, and the trial’s access model have been explicitly agreed.

1

Identity before access

Protected platform data requires an authenticated user. Sessions can be explicitly ended and revoked when access should stop.

2

Separated business workspace

Records are scoped to the active tenant so one organisation's workspace is not treated as part of another.

3

Role-based capability

Configured roles determine which resources and actions each user can access, supporting useful work without blanket permissions.

4

Responsibility-aware records

Where configured, access can follow self, member, or team responsibility instead of granting every user a business-wide view.

Defence in depth

Useful access includes both permission and protection.

A successful permission test is not only “the right user can do the work.” It also confirms that another user cannot obtain the same data or action without the required role and responsibility.

  • Administrator-only actions remain unavailable to ordinary users.
  • Each role can reach the records required for its responsibilities.
  • Changed or removed access no longer remains available to the user.
  • Ended sessions cannot continue using the presented access token.

Configured for the organisation

Strong controls begin with clear users, roles, and responsibilities.

The platform enforces configured boundaries, while each organisation remains responsible for appropriate accounts, sensible role design, secure devices, careful data choices, and reporting unexpected access.

Grant only what is needed

Start with the actions required for each responsibility and expand access deliberately when a genuine need appears.

Use individual accounts

Avoid shared credentials so access, activity, logout, and feedback can be tied to the correct tester.

Respond to unexpected access

Unexpected visibility, incorrect denial, or access continuing after logout should be reported immediately.

See how the platform is managed.

See what is managed during beta and what must be agreed before using important data.

Explore managed hosting