A locked records cabinet and key-card reader in a small office closet.

Security

Security built into TeamDots.

TeamDots is designed with security at every layer — from authentication and access control to tenant isolation, auditing, data protection, and infrastructure security.

Protect people, customers, documents, communication, and business data without slowing down the work. Controls may vary by plan and configuration. This page describes the TeamDots security design. It is not a SOC 2, HIPAA, PCI DSS, or other certification unless we confirm a current attestation in writing.

Security architecture

Defense in depth
07 layers
  1. 01Identity
  2. 02Authentication
  3. 03Tenant Access
  4. 04Roles & Permissions
  5. 05Application Authorization
  6. 06Data Protection
  7. 07Audit & Monitoring

Independent controls working together across every organization boundary.

01

Identity & access

Verify every user and keep access current throughout the account lifecycle.

01

Secure authentication

Protect access from the first sign-in

TeamDots provides centralized authentication for accessing your organization.

Security capabilities include

  • Secure sign-in
  • Multi-factor authentication policy (sign-in challenge rolling out)
  • Password security policies
  • Session management
  • Session expiration
  • Account lockout protections
  • Authentication monitoring
  • Secure password reset
  • Email verification
  • Device and session controls

Organizations can establish authentication requirements appropriate for their users.

02

Multi-Factor Authentication

Add another layer of protection

Passwords alone should not be the only protection for important business information.

TeamDots includes a tenant security-policy setting that can require multi-factor authentication.

The sign-in MFA challenge is being introduced as that capability is enabled for a workspace.

MFA enrollment and challenge are not generally available on every workspace yet.

03

Single Sign-On

Use your organization's identity provider

Enterprise single sign-on with an identity provider is planned. It is not generally available today.

When available, Single Sign-On is intended to help organizations centralize

  • User authentication
  • Access management
  • Account provisioning
  • Employee onboarding
  • Employee offboarding
  • Security policies

Do not treat this section as a current SSO capability. Availability will vary by plan and configuration when it ships.

04

Secure Sessions

Control how authenticated sessions are used

TeamDots manages authenticated sessions to help protect users after sign-in.

Organizations can establish policies around

  • Session expiration
  • Inactivity
  • Authentication renewal
  • Concurrent sessions
  • Device access
  • Session revocation

If access should no longer be available, sessions can be invalidated.

05

Account Lifecycle Management

Control access from onboarding through offboarding

Security doesn't stop at sign-in.

TeamDots helps organizations manage access throughout a user's relationship with the organization.

Onboarding
  1. Invite a user
  2. Verify identity
  3. Assign organization
  4. Assign role
  5. Grant appropriate access
Role Change
  1. Update responsibility
  2. Update roles
  3. Adjust permissions
  4. Maintain audit history
Offboarding
  1. Deactivate access
  2. Revoke sessions
  3. Remove permissions
  4. Preserve organizational records

Business records remain with the organization even when a person no longer has access.

06

Customer and External Access

Keep external access separate from internal access

Customers, vendors, clients, parents, members, and other external users should not automatically receive the same access as employees or internal users.

TeamDots separates internal organization access from external portal access.

Each experience can have its own permissions and capabilities.

This allows organizations to collaborate externally without exposing internal business information.

02

Authorization & tenancy

Keep organizations isolated and give each person only the access their work requires.

01

Your data belongs to your organization

TeamDots is built as a multi-tenant business platform with strong separation between organizations.

Your organization's users, customers, documents, workflows, billing information, and other business records remain associated with your TeamDots environment.

Designed for

  • Tenant data isolation
  • Organization-specific access
  • Role-based permissions
  • Controlled cross-module access
  • Secure application boundaries
  • Auditable activity

Users only receive access to the organizations and information they are authorized to use.

02

Roles & Permissions

Give users access to what they need

Not every person in an organization should have access to everything.

TeamDots uses permission-based access controls to help organizations determine what users can see and what actions they can perform.

Control access by

  • Role
  • Responsibility
  • Team
  • Organization unit
  • Location
  • Module
  • Feature
  • Action
  • Record where supported
Administrator

Manage organization-wide configuration.

Manager

Manage teams, work, schedules, and related information.

Team Member

Access the information required to perform assigned work.

Billing User

Access invoices, payments, and financial operations.

Read-Only User

View authorized information without changing it.

Organizations can configure access around how they operate.

03

Least-Privilege Access

Access only what is necessary

TeamDots is designed around the principle of least privilege.

Users should receive the minimum level of access necessary to perform their responsibilities.

As roles change, access can be adjusted without restructuring the entire organization.

This helps reduce unnecessary exposure of sensitive business information.

04

Organization & Tenant Isolation

Every organization operates within its own security boundary

TeamDots is designed so organizational data remains separated between tenants.

Tenant context is established before users access organization-specific information.

This boundary applies across areas such as

  • People
  • Customers
  • Teams
  • Work
  • Calendars
  • Communication
  • Documents
  • Configuration

Tenant isolation is a fundamental part of the TeamDots platform architecture—not simply a filter added to the user interface.

Organizations that need a stronger boundary than shared multi-tenancy can run TeamDots on a dedicated cloud instance — Azure, AWS, or Google Cloud. See dedicated deployment pricing

05

Security Policies

Configure security around your organization

Organizations have different security requirements.

TeamDots can provide configurable policies such as

  • MFA requirements
  • Session policies
  • Authentication requirements
  • Password policies
  • Access restrictions
  • User status controls
  • Invitation policies
  • Administrative permissions

Enterprise organizations can apply additional controls depending on their requirements.

03

Data protection

Protect business information, documents, files, payments, and recovery paths.

01

Data Protection

Protecting information while it moves and while it is stored

TeamDots is designed to protect business information throughout its lifecycle.

Security controls can include

  • Encryption for data in transit
  • Encryption for stored data where the host or storage provider is configured to encrypt at rest
  • Secure credential storage
  • Protected authentication tokens
  • Secrets management
  • Controlled storage access
  • Secure application communication

Sensitive credentials are separated from application source code and managed using appropriate security controls.

02

Document Security

Protect business documents and files

Documents often contain some of an organization's most important information.

TeamDots applies the platform's access model to documents and files.

Document security can include

  • Permission-controlled access
  • Organization isolation
  • Version history
  • Access history
  • Secure storage
  • Controlled downloads
  • Record-level relationships
  • Retention policies
  • Administrative controls

Documents remain connected to the business records they belong to while respecting the user's permissions.

03

Secure File Uploads

Treat uploaded content carefully

File uploads can create security risks if they are not handled appropriately.

TeamDots is designed to apply controls around uploaded files, including

  • File type validation
  • File size restrictions
  • Secure storage
  • Controlled access
  • Metadata validation
  • Malware scanning where a storage account is configured for it

Uploads are handled as protected business content rather than publicly accessible files. Malware scanning is not enabled on every storage account.

04

Backups & Recovery

Prepare for unexpected events

Protecting data also means planning for recovery.

TeamDots infrastructure is designed to support

  • Regular backups
  • Backup monitoring
  • Database recovery
  • Storage recovery
  • Restoration procedures
  • Business continuity planning

Backup and retention policies can vary based on service configuration and organizational requirements.

05

Payment Security

Keep payment information protected

Where TeamDots supports electronic payments, payment processing can be handled through supported payment providers.

TeamDots is designed to minimize unnecessary handling of sensitive payment credentials and use provider-hosted or tokenized payment capabilities where appropriate.

Payment providers may maintain their own security and compliance requirements.

06

Privacy by Design

Access should have a purpose

TeamDots is designed around controlled access to organizational information.

Security and privacy considerations include

  • Collecting information for defined business purposes
  • Limiting access
  • Maintaining organizational ownership
  • Tracking important activity
  • Providing retention controls
  • Supporting data lifecycle management

Organizations remain responsible for determining what information they collect and how it should be used.

How we handle personal information as a business and as a processor is described in the Privacy Policy

04

Platform security

Layer application, infrastructure, environment, monitoring, and notification controls.

01

Application Security

Security is part of how TeamDots is built

Security is considered throughout application development rather than added after features are completed.

Our development approach includes practices around

  • Input validation
  • Output encoding
  • Authentication
  • Authorization
  • Secure APIs
  • Dependency management
  • Secret management
  • Error handling
  • Secure configuration
  • Logging
  • Code review
  • Automated testing

We continually improve these controls as TeamDots evolves.

02

Infrastructure Security

Multiple layers of protection

TeamDots infrastructure is designed with separation between application, data, networking, and administrative components.

Security controls can include

  • Network segmentation
  • Restricted administrative access
  • Firewalls
  • Secure service communication
  • Secrets management
  • Monitoring
  • Logging
  • Backup controls
  • Environment separation
  • Infrastructure access policies

Production access is limited to authorized administrative personnel and systems.

03

Environment Separation

Keep development and production separate

TeamDots uses separate application environments to reduce the risk of development activities affecting production systems.

Environment separation can cover

  • Development
  • Testing
  • Staging
  • Production

Credentials, configurations, databases, and deployment processes are managed separately where appropriate.

04

Monitoring & Logging

Security requires visibility

TeamDots monitors application and infrastructure activity to help identify problems and unusual behavior.

Monitoring can include

  • Application events
  • Authentication events
  • Infrastructure health
  • API activity
  • Database operations
  • Application errors
  • Security-related events

Logging helps our team investigate incidents and improve platform reliability.

05

Security Notifications

Keep administrators informed

Important security events can generate notifications where appropriate.

Examples can include

  • Authentication events
  • Account changes
  • Password changes
  • MFA changes
  • Permission changes
  • Integration changes
  • Administrative actions

Organizations can establish notification preferences based on their needs.

05

Connected systems

Secure the APIs, integrations, and webhooks that connect TeamDots to other services.

01

API Security

Securely connect other systems to TeamDots

TeamDots APIs use authenticated and authorized access.

API security capabilities can include

  • Authentication tokens
  • Scoped access
  • Permission validation
  • Tenant validation
  • API credentials
  • Rate limits
  • Request validation
  • Access logging
  • Credential rotation where the credential type supports it

An API request must satisfy the same fundamental access rules as a user interacting with TeamDots.

02

Integration Security

Connect external services without exposing more than necessary

TeamDots can integrate with email, messaging, payment, storage, identity, and other external providers.

Integrations are designed around controlled access.

Integration security includes considerations such as

  • Protected credentials
  • Scoped permissions
  • Secret management
  • Token expiration
  • Credential rotation
  • Integration-specific authorization
  • Activity monitoring

Connections can be disabled when they are no longer required.

03

Webhook Security

Secure system-to-system events

Signed outbound webhooks are not generally available today. When that capability ships, integrations are intended to use controls designed to verify requests and protect data exchange.

Intended capabilities include

  • Signed webhook requests
  • Secure endpoints
  • Secret rotation
  • Delivery history
  • Retry controls
  • Event filtering

Do not treat signed webhooks as a current product capability.

06

Assurance & visibility

Make important access and activity visible for investigation and governance.

01

Audit History

Know what happened

Visibility is an important part of security.

TeamDots maintains audit and activity information for important operations across the platform.

Depending on the feature, audit information can include

  • Who performed an action
  • What action was performed
  • When it occurred
  • What record was affected
  • Previous and updated values
  • Sign-in activity
  • Permission changes
  • Workflow activity
  • Document activity
  • Administrative actions

This gives administrators greater visibility into how their organization is using TeamDots.

02

Access Logging

Monitor access to important information

TeamDots can record access to protected resources where enhanced visibility is required.

Access information may include

  • User
  • Resource
  • Action
  • Date and time
  • Application context
  • Request information
  • Result

These records can help organizations investigate security events and understand access patterns.

Working together

Platform protection meets operational discipline.

Security is a shared responsibility

TeamDots protects the platform and provides security controls. Organizations also protect their environment.

We recommend that customers

  • Require MFA
  • Use strong authentication policies
  • Assign least-privilege permissions
  • Review access regularly
  • Remove access promptly when people leave
  • Protect administrator accounts
  • Review audit information
  • Keep integrations current
  • Train users on security practices

Compliance-ready controls

TeamDots is designed with controls that can support security and compliance programs.

Control foundations

  • Authentication
  • Access control
  • Tenant isolation
  • Audit logging
  • Data protection
  • Security policies
  • Data retention
  • Monitoring
  • Administrative controls
Contact us about security & compliance

The strongest security combines platform protections with good organizational practices. Specific certifications should be evaluated for the service, configuration, and contract.

Build with confidence

Build your business on a secure foundation.

Your business platform contains some of your organization's most important information. TeamDots is designed to help protect it while giving your team the access they need to get work done.

  • Secure access
  • Controlled permissions
  • Protected data
  • Auditable activity