Skip to content
Security & governance

Built to be the system of record

When Cairn holds your books and your operation, security isn't a feature, it's the foundation. Here's exactly what's in place today, and what's on the roadmap.

In place today

Multi-tenant data isolation

Every record is scoped to your organization, so your data is never commingled with another company's: row-level security at the database, plus organization scoping enforced in every server read.

Role-based access control

Granular RBAC with 25 built-in roles, custom roles, and segregation-of-duties checks (the person who approves a transaction can't be the one who created it).

Audit history on every record

Complete, tamper-evident audit history on every record. AI-drafted entries keep a link back to the exact source document, the model that drafted them, and the person who authorized the post.

Login audit trail

Every sign-in, failed attempt, sign-out, and workspace switch is recorded with IP address, browser, and timestamp — an immutable trail your admins can review under Settings, the way a system of record should.

Your data is yours

Your business data, formulations, recipes, pricing, and financials are never used to train shared or public foundation models.

Encryption

Data is encrypted with TLS 1.2+ in transit and AES-256 at rest on managed Postgres.

Backups & recovery

Automated daily backups with point-in-time recovery, running on managed infrastructure.

Hosting

Managed cloud infrastructure with isolated tenant data, operated and patched by the platform providers underneath it.

Human-in-the-loop AI

AI routines stage records for review; nothing posts to your ledger without explicit one-click human approval.

On the roadmap

Formal compliance certification

We're building toward SOC 2 Type II, which requires an independent auditor and a multi-month observation window. It is in progress, not yet certified, and we won't claim a badge we haven't earned. GDPR-aligned data handling and a formal data processing agreement are part of the same track. We're happy to walk security and compliance teams through our current controls and timeline on a call.

A dedicated-tenant deployment, your own isolated database in a data region of your choice, is on the same roadmap for enterprise organizations.

Talk to us about security

Report a vulnerability: najib@cairnerp.com or saahir@cairnerp.com

Replace your legacy ERP. In weeks.

Twelve months and six figures used to be the price of admission. Not anymore.

Get a demo

White-glove implementation No per-transaction fees No surprise invoices