Skip to main content
CheckSync logo

Security

Built to be trusted
on operational sites.

CheckSync uses authentication, role-based access, audit logging and controlled terminal provisioning to support secure site operations - hosted on Cloudflare infrastructure with per-client deployment separation.

CheckSync secures site data through Auth0-managed dashboard authentication with MFA support, eleven role-based permission levels, site-scoped user access, append-only audit logging, controlled terminal provisioning with site-specific keys, and per-client isolated deployment on Cloudflare infrastructure. No shared database exists between customers.

How it works

Security built into every layer.

From dashboard login to terminal sign-in, access is controlled, logged and isolated at every point.

Auth0-secured dashboard access

Dashboard login is handled through Auth0, a dedicated identity platform with MFA support, session management and secure token handling - not a home-built auth system.

Role-based permissions

Eleven distinct roles control what each user can see and do. Receptionists, operations managers, finance teams and agency admins each get access scoped to their function, nothing more.

Site-level access control

Users are scoped to the sites they are assigned to. A manager at one depot cannot view data from another site unless explicitly granted access.

Append-only audit logs

Attendance records, sign-in events and administrative actions are written to an append-only audit log. Records support internal accountability and evidence trails.

Controlled terminal provisioning

Each terminal is provisioned with a site-specific key. Unprovisioned devices cannot access site data. Provisioning is handled by authorised operators only.

Cloudflare-hosted infrastructure

The API, dashboard and public site run on Cloudflare's global network, including DDoS protection, WAF capabilities and edge-proxied traffic handling at every request.

Audit records

Every event timestamped
and recorded.

CheckSync maintains a structured log of attendance events, sign-in and sign-out activity, biometric verification results and administrative actions.

Records include site, timestamp, person type and event outcome. Authorised users can search, filter and export logs from the dashboard. Biometric audit records are kept in a separate log with independent retention controls.

dashboard.checksync.ultrafastdigital.com
CheckSync dashboard audit log screen showing timestamped sign-in events

Deployment model

Per-client deployment separation.

CheckSync can be deployed with client-specific separation to support stronger data isolation and procurement confidence.

Each client deployment operates as its own isolated environment. There is no shared database between clients, the database boundary is the client boundary. This supports data isolation requirements common in enterprise procurement and regulated industries.

Access gateway

Clients reach their own environment.

The client login gateway routes each organisation to their own dedicated deployment using a hashed access code, not a shared multi-tenant login pool.

Organisation slugs are resolved server-side against a secure KV store. Access codes are SHA-256 hashed with a server-side pepper and compared using timing-safe logic to resist enumeration.

Certifications

Designed with recognised frameworks in mind.

CheckSync is designed with security and compliance controls informed by recognised frameworks such as ISO 27001, SOC 2 principles and GDPR expectations. Formal certification is not currently claimed.

Its technical design includes controls commonly expected in regulated SaaS environments - including authentication, role-based permissions, audit trails, site and client data separation, secure deployment practices and GDPR-conscious data handling. For procurement teams requiring a written security summary, this can be provided on request during a pilot discussion.

Get started

Security questions before committing?

Talk directly to the team behind CheckSync. No sales layer, no ticket queue - a direct conversation about your site, your requirements and what CheckSync can evidence.