Security

Built so the foundation is never the weak point.

Ordanta holds your people’s details, your commercial pricing and your safety records. This page describes, in plain terms, the controls that protect them.

Accounts and access

Signing in

Password protection

Passwords are stored as salted hashes and never in plain text. New accounts must set their own password on first login. Reset links are single-use and expire quickly.

Two-factor authentication

Authenticator-app codes are mandatory for supervisor, administrator and finance-tier roles, and available to everyone else. Backup codes are issued so a lost phone does not lock someone out.

Lockout and session control

Repeated failed attempts lock that account temporarily, without affecting colleagues on the same office connection. An administrator can revoke a user’s sessions instantly, platform-wide.

Permissions

People see what their role needs, and no more.

Access is granted per module and per role. Field workers see their own work, supervisors approve, managers run operations, administrators configure the organisation. Every API request is checked against the role grid, not just the screens.

Segregation of duties

Purchase orders require a requester, an approver and an authoriser who are different people. Timesheets are approved by someone other than the worker who signed them.

Client portal isolation

Your clients log in separately and only ever see the projects you have granted, section by section. The portal is read-only by design.

Multi-company boundaries

Organisations in a company group are isolated unless a group administrator explicitly grants cross-company access to a named person.

Module toggles

A module that is switched off for your organisation is switched off at the API as well as in the menu.

Data

Where your information lives and how it is handled.

Encryption

All traffic is served over HTTPS. Integration credentials, two-factor secrets and storage keys are encrypted at rest.

Files and documents

Uploaded files are held in private object storage and served through short-lived signed links. Uploads are type-checked before they are stored.

Audit trails

Timesheets, leave, purchase orders, compliance records and document acknowledgements each carry a history of who changed what and when. Security events, including logins, failures, lockouts and revocations, are logged for administrators.

Hardened by default

Hardened defaults throughout: strict browser security headers, rate limiting on sensitive endpoints, protection against duplicate submissions, and secure session cookies.

Document intelligence stays local

Indexing of your documents happens on the Ordanta server. Only the passages relevant to a question are sent to the AI provider when the optional composed-answer mode is used, and answers cite their sources.

Your own accounts

Ordanta connects to your Xero organisation, your email domain and your storage bucket under credentials you own and can revoke. There is no shared tenancy of third-party accounts.

Questions

Common questions

Who can turn on two-factor authentication?

Everyone can, under Settings and Security in the app. Supervisor, administrator and finance-tier accounts are required to enrol before they can continue.

Can we remove access for someone who has left immediately?

Yes. An administrator can revoke every active session for a user in one action, and deactivate the account. The revocation is recorded in the security log.

Can we see who approved a timesheet or purchase order?

Yes. Approvals, rejections and sign-offs are recorded against the record with the user and timestamp, and the segregation-of-duties rules mean the same person cannot fill every role.

Do you need our Xero login?

No. Xero is connected through its standard authorisation flow from within Ordanta. You approve the connection in Xero, and you can disconnect it there at any time.

How do I report a security concern?

Use the contact form and mark the message as a security matter. We will acknowledge it and follow up directly.

Want the detail?

We are happy to walk your IT or compliance lead through the architecture, hosting arrangements and controls before you commit.