Enterprise Privacy & Tenant Isolation Policy
ISO 27001 & Multi-Tenant Data Protection Standards
1. Strict Multi-Tenant Data Isolation
Every commercial entity on the SOF-XI Cloud Platform operates in an isolated tenant container (tenantId). Client invoices, stock ledgers, vendor quotes, and work orders are never commingled or visible across tenants.
2. Google Workspace & SSO Data Processing
When authenticating via Google Workspace Single Sign-On, our system validates the encrypted ID token against Google's OAuth endpoints. We collect only verified profile details (name, email) necessary to associate your session with your enterprise member profile. We never sell or share user telemetry with third-party advertisers.
3. Encrypted Document Storage Vaults
Generated A4 estimates, proforma invoices, and work order attachments are archived in isolated Google Drive client storage vaults with AES-256 rest encryption and TLS 1.3 in-transit security.
4. Data Retention & Immutable Audit Logs
All stock transactions, accounting journal entries, and system login attempts are recorded in immutable, timestamped audit logs. Tenant data is retained in accordance with statutory accounting retention requirements (minimum 7 years).