Built for governance, not just reporting
Soilo is designed with SOC 2 and ISO 27001-aligned controls in mind — role-based access, maker-checker approvals, encryption, audit trails, and data residency controls for enterprise and government programmes.
Governance built into the workflow, not bolted on
Role-based access control
Granular RBAC assigns read, edit, approve, and admin permissions at module, programme, and site level. No one sees or changes what they are not authorised for.
Maker-checker workflows
Two-person control for critical data entry and changes. The maker enters, the checker approves — with a full record of both actions.
Immutable audit trail
Every create, edit, approve, and delete action is recorded with user, timestamp, and reason. The trail cannot be modified after the fact.
Version history
Earlier versions of any record can be reconstructed and compared. Nothing is permanently lost or silently overwritten.
Encryption in transit and at rest
Data is encrypted using TLS in transit and encrypted at rest. Key management details are provided in enterprise security documentation.
Data residency controls
Data storage location, backup frequency, and residency requirements are configured per enterprise engagement to meet regulatory and sovereignty needs.
Single sign-on and authentication
Enterprise SSO integration and multi-factor authentication are supported. Authentication configuration is scoped during onboarding.
SOC 2 and ISO 27001-aligned design
Soilo is designed with SOC 2 and ISO 27001-aligned security controls in mind. Formal certification timelines will be communicated when confirmed.
Enterprise procurement and security review
Soilo provides security documentation, data processing agreements, and architecture overviews to support enterprise procurement review and due diligence. Contact us to request security and compliance documentation for your evaluation.
Note: Soilo does not currently hold SOC 2 or ISO 27001 certification. The platform is designed with these frameworks' control principles in mind. Certification status will be updated as formal assessments are completed.
Security and audit — FAQ
Security documentation available on request
Book a demo or contact us to request security architecture details, data processing agreements, and governance documentation.