IM EnterpriseProduct Guide

Security & Compliance

Enterprise-grade security designed for organizations that cannot rely on trust alone — enforced at the database, application, and policy layers.

Sign-in & access

Secure login

Email and password authentication with strong password requirements configurable by your administrators.

Ideal for: Every deployment — the foundation of workforce access.

Controlled registration

Public sign-up can be enabled or disabled per organization.

Ideal for: Pilot programs vs. locked-down production environments.

Session security

Short-lived login sessions with secure refresh — users stay signed in safely across devices.

Ideal for: Mobile and multi-device workforces.

Device session management

Users can see every device where they are logged in and revoke access remotely.

Ideal for: Offboarding, lost devices, and security incident response.

First-time setup wizard

On a fresh deployment, create your organization and administrator account in minutes.

Ideal for: New on-premises installations and proof-of-concept deployments.

Multi-factor authentication & SSO

Multi-factor authentication (MFA)

Add an authenticator app as a second layer of protection beyond passwords.

Ideal for: Any organization serious about account security.

Require MFA for everyone

Administrators can mandate MFA for all users — common in government and finance presets.

Ideal for: Regulated industries and zero-trust security programs.

Single sign-on (SSO)

Connect your existing identity provider (SAML or OIDC) so employees use corporate credentials.

Ideal for: Enterprises with Azure AD, Okta, Google Workspace, or other IdPs.

Automatic account provisioning

New employees are created on first SSO login — no manual account setup.

Ideal for: Large organizations with high onboarding volume.

SCIM provisioning

Automate user and group lifecycle from your identity provider — create, update, and deactivate accounts automatically.

Ideal for: IT teams managing hundreds or thousands of users.

Access control & isolation

Role-based access

Five built-in roles — Owner, Admin, Moderator, Member, Guest — with customizable permission overrides.

Ideal for: Organizations that need fine-grained control without complexity.

Granular permissions

Control who can create channels, upload files, use AI, manage SSO, and view audit logs.

Ideal for: Security teams defining least-privilege policies.

Database-level tenant isolation

Each organization's data is isolated at the database layer — not just by application logic.

Ideal for: Multi-tenant MSPs and holding companies where cross-tenant leakage is unacceptable.

Platform operator access

Separate, audited access for platform operators managing multiple brands — never mixed with customer data access.

Ideal for: MSPs and vendors running the platform for many customers.

Audit & compliance

Immutable audit log

Every security-sensitive action is recorded in an append-only log that cannot be altered.

Ideal for: Compliance audits, forensic investigation, and SOC 2 readiness.

Personal data export

Employees can export their own data on request — supporting GDPR and privacy regulations.

Ideal for: EU deployments and privacy-conscious organizations.

Strong password policies

Minimum length and complexity rules enforced at registration and password change.

Ideal for: Baseline security hygiene for every deployment.

Rate limiting & abuse protection

Automatic throttling on login, search, AI, and upload endpoints to prevent abuse.

Ideal for: Internet-facing and high-traffic deployments.

No topics match your search. Try different keywords.

Questions about this feature? Contact our team or visit the product overview.