Tenant separation
Every record carries the workspace it belongs to, and every read is scoped to the workspace of the person asking, in one place in the code that no request can widen. A provider reads across the customer workspaces it operates and nothing else; a supplier reads the tenders it is invited to while they are undecided, the work it was awarded, and nothing else. A record in another workspace answers exactly like a record that does not exist.
The product's own test suite dispatches every route in the API as every role and with no session at all, on every deploy, and fails the deploy if any route answers a stranger's record or breaks.
Access and sign-in
- Roles. Fifteen roles across customer, provider, supplier and platform consoles, each with a fixed permission list. Nobody holds a permission by accident.
- Second factor. Time-based one-time codes with recovery codes. A workspace can require it of everybody; the platform can require it by role, and of its own operators before they see any workspace.
- Sessions. A session ends after 24 hours without use and after 30 days regardless; a workspace may shorten both and may restrict sign-in to its own network addresses.
- Passwords. Argon2id; sign-in throttled per account and per address; lockouts are visible to the workspace's administrator, who can lift them.
- Support access. Platform staff cannot open a workspace. They ask, naming a ticket, a purpose and a time, and somebody in the workspace approves or refuses. Every screen viewed under an approval is listed for the customer.
- Four eyes. Money and destructive operator actions need a second operator.
Encryption and hosting
Hosted on Hetzner Online GmbH in Germany, with backups in Finland. Every connection is TLS; certificates are issued and renewed automatically. Uploaded files are scanned for malware before they are stored, and photographs have their camera metadata (location, device, owner) removed before anybody can download them. Off-host backups are encrypted with a key that never leaves the host and the owner's password manager.
Backups and recovery
| Target | Figure | How |
|---|---|---|
| Recovery point (most data lost) | 6 hours | Full dump nightly, database-only dumps three times a day, each copied off-host and verified by checksum |
| Recovery time (longest outage) | 4 hours from the decision to rebuild | Scripted host, atomic releases, rehearsed restore |
| Backup retention | 14 days on the host · 35 days off-host | Local pruning; bucket lifecycle rule |
| Restore rehearsal | Twice a week | Sunday from the local archive, Wednesday from the off-host copy with the key, both into a scratch database that is checked and dropped |
A restore replays every recorded erasure against the restored copy before it is trusted, so a person the product has promised to forget does not come back with the backup.
Audit and accountability
Every decision that matters (money, roles, access, tenders, exports, downloads) is written to a log the moment it happens, under the workspace it happened to, with who did it, from which organisation, and when. A workspace reads its own log, filters it by date and by whether the act came from outside (its provider or the platform), and exports it as a file. Nothing in the log can be edited or removed by anybody.
Retention and leaving
- Closed cases are emptied of personal data 36 months after closure, or sooner if the workspace sets a shorter period (12 months minimum). Never while a legal hold names the case.
- Sign-in and security records are kept 13 months.
- Accounting material is kept five years from the end of the financial year, as the law requires.
- A workspace that leaves is read-only and exportable for 90 days, as one file with everything in it, and is deleted 30 days after that.
- Erasure requests are planned, approved as one exact plan, executed and certified; access and rectification requests are written down with their 30-day clock and answered with an export or a note.
Testing and incidents
Every deploy runs a suite of more than 1,700 checks against a real database, a probe that attacks every route as every role, and is rolled back automatically if the health check fails afterwards. Concurrency is tested with real parallel requests against the writes that must only happen once. Capacity has been measured at 3,000 people, 300 locations and 50,000 cases in one workspace.
An independent penetration test has not yet been commissioned. This page will name the firm and link to the summary when one has.
Security incidents follow a written runbook: contain, assess, tell every affected controller without undue delay (in practice within 24 hours) through a notice that reaches everybody who answers for the workspace and cannot be muted, and support their notification to the Danish Data Protection Agency within 72 hours.
Sub-processors
| Who | What for | Where |
|---|---|---|
| Hetzner Online GmbH | Compute, database and off-host backup storage | Germany · Finland |
| Postmark (ActiveCampaign, LLC) | Transactional email | EU sending region |
| Apple Inc. · Google LLC | Push notifications to enrolled phones | Per the platform |
The processor is Fogito ApS, CVR 46429370, Denmark, which has a data protection officer. Each workspace can read its own Article 30 processing register, generated from its records, in its privacy screen.
Accessibility
FogiDesk aims at WCAG 2.1 AA. Every dialog is keyboard-operable and closes on Escape; status messages are announced to screen readers; text contrast is measured by the test suite against the stylesheet; every control has a name. Known gaps are tracked in the audit document and fixed in order; if you meet one, write to the contact below and it goes to the front of the list.