Security

Security built into TeamDots

Your business depends on the information you manage every day.

TeamDots is designed with security at every layer—from authentication and access control to tenant isolation, auditing, data protection, and infrastructure security.

Give organizations the controls they need to protect their people, customers, documents, communication, and business data.

Your data belongs to your organization

TeamDots is built as a multi-tenant business platform with strong separation between organizations.

Your organization's users, customers, documents, workflows, billing information, and other business records remain associated with your TeamDots environment.

Designed for

Users only receive access to the organizations and information they are authorized to use.

Secure authentication

Protect access from the first sign-in

TeamDots provides centralized authentication for accessing your organization.

Security capabilities include

Organizations can establish authentication requirements appropriate for their users.

Multi-Factor Authentication

Add another layer of protection

Passwords alone should not be the only protection for important business information.

TeamDots supports multi-factor authentication to provide an additional verification step when users sign in.

Organizations can establish MFA requirements based on their security policies.

Single Sign-On

Use your organization's identity provider

Organizations can connect TeamDots with supported enterprise identity providers.

Single Sign-On can help organizations centralize

Enterprise identity capabilities may vary by TeamDots plan and configuration.

Roles & Permissions

Give users access to what they need

Not every person in an organization should have access to everything.

TeamDots uses permission-based access controls to help organizations determine what users can see and what actions they can perform.

Control access by

Administrator

Manage organization-wide configuration.

Manager

Manage teams, work, schedules, and related information.

Team Member

Access the information required to perform assigned work.

Billing User

Access invoices, payments, and financial operations.

Read-Only User

View authorized information without changing it.

Organizations can configure access around how they operate.

Least-Privilege Access

Access only what is necessary

TeamDots is designed around the principle of least privilege.

Users should receive the minimum level of access necessary to perform their responsibilities.

As roles change, access can be adjusted without restructuring the entire organization.

This helps reduce unnecessary exposure of sensitive business information.

Organization & Tenant Isolation

Every organization operates within its own security boundary

TeamDots is designed so organizational data remains separated between tenants.

Tenant context is established before users access organization-specific information.

This boundary applies across areas such as

Tenant isolation is a fundamental part of the TeamDots platform architecture—not simply a filter added to the user interface.

Data Protection

Protecting information while it moves and while it is stored

TeamDots is designed to protect business information throughout its lifecycle.

Security controls can include

Sensitive credentials are separated from application source code and managed using appropriate security controls.

Secure Sessions

Control how authenticated sessions are used

TeamDots manages authenticated sessions to help protect users after sign-in.

Organizations can establish policies around

If access should no longer be available, sessions can be invalidated.

Audit History

Know what happened

Visibility is an important part of security.

TeamDots maintains audit and activity information for important operations across the platform.

Depending on the feature, audit information can include

This gives administrators greater visibility into how their organization is using TeamDots.

Access Logging

Monitor access to important information

TeamDots can record access to protected resources where enhanced visibility is required.

Access information may include

These records can help organizations investigate security events and understand access patterns.

Document Security

Protect business documents and files

Documents often contain some of an organization's most important information.

TeamDots applies the platform's access model to documents and files.

Document security can include

Documents remain connected to the business records they belong to while respecting the user's permissions.

Secure File Uploads

Treat uploaded content carefully

File uploads can create security risks if they are not handled appropriately.

TeamDots is designed to apply controls around uploaded files, including

Uploads are handled as protected business content rather than publicly accessible files.

API Security

Securely connect other systems to TeamDots

TeamDots APIs use authenticated and authorized access.

API security capabilities can include

An API request must satisfy the same fundamental access rules as a user interacting with TeamDots.

Integration Security

Connect external services without exposing more than necessary

TeamDots can integrate with email, messaging, payment, storage, identity, and other external providers.

Integrations are designed around controlled access.

Integration security includes considerations such as

Connections can be disabled when they are no longer required.

Webhook Security

Secure system-to-system events

When TeamDots communicates with external systems through webhooks, those integrations can use security controls designed to verify requests and protect data exchange.

Capabilities may include

Only the information required for the selected integration should be shared.

Application Security

Security is part of how TeamDots is built

Security is considered throughout application development rather than added after features are completed.

Our development approach includes practices around

We continually improve these controls as TeamDots evolves.

Infrastructure Security

Multiple layers of protection

TeamDots infrastructure is designed with separation between application, data, networking, and administrative components.

Security controls can include

Production access is limited to authorized administrative personnel and systems.

Environment Separation

Keep development and production separate

TeamDots uses separate application environments to reduce the risk of development activities affecting production systems.

Environment separation can cover

Credentials, configurations, databases, and deployment processes are managed separately where appropriate.

Backups & Recovery

Prepare for unexpected events

Protecting data also means planning for recovery.

TeamDots infrastructure is designed to support

Backup and retention policies can vary based on service configuration and organizational requirements.

Monitoring & Logging

Security requires visibility

TeamDots monitors application and infrastructure activity to help identify problems and unusual behavior.

Monitoring can include

Logging helps our team investigate incidents and improve platform reliability.

Security Notifications

Keep administrators informed

Important security events can generate notifications where appropriate.

Examples can include

Organizations can establish notification preferences based on their needs.

Account Lifecycle Management

Control access from onboarding through offboarding

Security doesn't stop at sign-in.

TeamDots helps organizations manage access throughout a user's relationship with the organization.

Onboarding
  • Invite a user
  • Verify identity
  • Assign organization
  • Assign role
  • Grant appropriate access
Role Change
  • Update responsibility
  • Update roles
  • Adjust permissions
  • Maintain audit history
Offboarding
  • Deactivate access
  • Revoke sessions
  • Remove permissions
  • Preserve organizational records

Business records remain with the organization even when a person no longer has access.

Customer and External Access

Keep external access separate from internal access

Customers, vendors, clients, parents, members, and other external users should not automatically receive the same access as employees or internal users.

TeamDots can separate internal organization access from external portal access.

Each experience can have its own permissions and capabilities.

This allows organizations to collaborate externally without exposing internal business information.

Payment Security

Keep payment information protected

Where TeamDots supports electronic payments, payment processing can be handled through supported payment providers.

TeamDots is designed to minimize unnecessary handling of sensitive payment credentials and use provider-hosted or tokenized payment capabilities where appropriate.

Payment providers may maintain their own security and compliance requirements.

Security Policies

Configure security around your organization

Organizations have different security requirements.

TeamDots can provide configurable policies such as

Enterprise organizations can apply additional controls depending on their requirements.

Privacy by Design

Access should have a purpose

TeamDots is designed around controlled access to organizational information.

Security and privacy considerations include

Organizations remain responsible for determining what information they collect and how it should be used.

Security is a shared responsibility

TeamDots protects the platform and provides organizations with security controls. Organizations also play an important role in protecting their environment.

We recommend that customers

The strongest security comes from combining platform protections with good organizational practices.

Compliance

Built with security and compliance requirements in mind

Different organizations and industries have different regulatory requirements. TeamDots is designed with controls that can support security and compliance programs, including:

Specific certifications, regulatory support, or compliance commitments should be evaluated based on the TeamDots service, configuration, and contractual requirements.

Contact Us About Security & Compliance

Defense in depth

Security at every layer

TeamDots uses multiple security layers to help protect your organization.

  1. Identity
  2. Authentication
  3. Tenant Access
  4. Roles & Permissions
  5. Application Authorization
  6. Data Protection
  7. Audit & Monitoring

No single security control should have to protect everything. TeamDots is designed around multiple layers working together.

Build your business on a secure foundation

Your business platform contains some of your organization's most important information. TeamDots is designed to help protect it while giving your team the access they need to get work done.

Connect your business with confidence.