Security & trust
Isolation, access control and auditability live in the data layer.
Security posture that is implemented per module is only as strong as the module that forgot. Planet B2B enforces tenancy, access and audit beneath the modules, so every capability inherits the same guarantees by construction rather than by discipline.
Database-level tenant isolation
Every tenant's data sits behind row-level security enforced by the database, not by application code. A query that omits the tenant predicate returns nothing rather than another organisation's records.
Hybrid RBAC / ABAC
Roles carry the baseline; attributes — clearance, nationality, initiative, classification — narrow it. Both are evaluated on every request, so an entitlement granted in one module cannot widen access in another.
Data classification tiers
Records and documents carry a classification that travels with them through workflows, exports and notifications. Handling rules are configured per tenant and enforced at the data layer.
Immutable audit trail
Every read, write and permission change is written to an append-only log with actor, tenant, classification and time. The trail does not stop at a module boundary, so a bid can be reconstructed end to end.
Field-level encryption / HSM
Sensitive fields are encrypted individually, with keys held in a hardware security module. In dedicated and on-premises deployments the keys are yours, and rotation is under your control.
Compliance-configurable
Retention, residency, approval thresholds and evidence export are configuration, not code. The same platform can meet one initiative's rules without loosening another's.
Framework positions
The platform is compliance-configurable rather than certified against a fixed list. We state posture honestly: the controls below are implemented and configurable, and we will walk your assessors through them.
GDPR / RODO
Configurable controls
SOC 2
Readiness
ISO 27001
Aligned controls
NIS2
Configurable controls
Where a framework says readiness or aligned, it means the controls are implemented and evidence is available — not that a certificate has been issued.
Bring your initiatives into one auditable environment.
Tell us about your initiative, your sovereignty constraints and the tools you are trying to retire. We will show you what a first module looks like.