Built so the foundation is never the weak point.
Ordanta holds your people’s details, your commercial pricing and your safety records. This page describes, in plain terms, the controls that protect them.
Signing in
Password protection
Passwords are stored as salted hashes and never in plain text. New accounts must set their own password on first login. Reset links are single-use and expire quickly.
Two-factor authentication
Authenticator-app codes are mandatory for supervisor, administrator and finance-tier roles, and available to everyone else. Backup codes are issued so a lost phone does not lock someone out.
Lockout and session control
Repeated failed attempts lock that account temporarily, without affecting colleagues on the same office connection. An administrator can revoke a user’s sessions instantly, platform-wide.
People see what their role needs, and no more.
Access is granted per module and per role. Field workers see their own work, supervisors approve, managers run operations, administrators configure the organisation. Every API request is checked against the role grid, not just the screens.
Segregation of duties
Purchase orders require a requester, an approver and an authoriser who are different people. Timesheets are approved by someone other than the worker who signed them.
Client portal isolation
Your clients log in separately and only ever see the projects you have granted, section by section. The portal is read-only by design.
Multi-company boundaries
Organisations in a company group are isolated unless a group administrator explicitly grants cross-company access to a named person.
Module toggles
A module that is switched off for your organisation is switched off at the API as well as in the menu.
Where your information lives and how it is handled.
Encryption
All traffic is served over HTTPS. Integration credentials, two-factor secrets and storage keys are encrypted at rest.
Files and documents
Uploaded files are held in private object storage and served through short-lived signed links. Uploads are type-checked before they are stored.
Audit trails
Timesheets, leave, purchase orders, compliance records and document acknowledgements each carry a history of who changed what and when. Security events, including logins, failures, lockouts and revocations, are logged for administrators.
Hardened by default
Hardened defaults throughout: strict browser security headers, rate limiting on sensitive endpoints, protection against duplicate submissions, and secure session cookies.
Document intelligence stays local
Indexing of your documents happens on the Ordanta server. Only the passages relevant to a question are sent to the AI provider when the optional composed-answer mode is used, and answers cite their sources.
Your own accounts
Ordanta connects to your Xero organisation, your email domain and your storage bucket under credentials you own and can revoke. There is no shared tenancy of third-party accounts.
Common questions
Who can turn on two-factor authentication?
Everyone can, under Settings and Security in the app. Supervisor, administrator and finance-tier accounts are required to enrol before they can continue.
Can we remove access for someone who has left immediately?
Yes. An administrator can revoke every active session for a user in one action, and deactivate the account. The revocation is recorded in the security log.
Can we see who approved a timesheet or purchase order?
Yes. Approvals, rejections and sign-offs are recorded against the record with the user and timestamp, and the segregation-of-duties rules mean the same person cannot fill every role.
Do you need our Xero login?
No. Xero is connected through its standard authorisation flow from within Ordanta. You approve the connection in Xero, and you can disconnect it there at any time.
How do I report a security concern?
Use the contact form and mark the message as a security matter. We will acknowledge it and follow up directly.
Want the detail?
We are happy to walk your IT or compliance lead through the architecture, hosting arrangements and controls before you commit.