Security & Compliance
Your data, protected
Phocus is built for manufacturers who take data seriously. Here's how we protect it.
Infrastructure
- •Hosted on Microsoft Azure (East US 2 region)
- •PostgreSQL database with automated daily backups
- •TLS 1.2+ encryption in transit for all connections
- •AES-256 encryption at rest for all stored data
Tenant Isolation
- •Every database query is scoped to your tenant — enforced at the application layer, not just by convention
- •Cross-tenant data access is architecturally impossible, not just policy-prohibited
- •Session tokens are scoped to your organization and expire after 30 days
Authentication
- •Passwords hashed with Scrypt (memory-hard, salted) — no plain-text storage
- •Microsoft SSO integration available (Azure AD / Entra ID)
- •Role-based access control: Admin, Power User, and User tiers
- •Rate-limited login attempts (10 per minute per IP)
Compliance Roadmap
- •SOC 2 Type II certification — in progress
- •Full audit trail for all data modifications
- •Data export available on request for portability
Have specific security questions? Our team is happy to walk through our architecture in detail during a demo or provide documentation for your IT review.
Contact Security Team