Security

Written from the code, not the brochure

Meskora holds your clients’ operational data, so this page describes how the product actually behaves — each of these is enforced in code and covered by tests.

Your workspace is isolated

Every record belongs to your workspace and every request is checked against it before anything is read or written. A record from another workspace answers exactly as one that never existed — not "forbidden", which would confirm it is there.

Sign-in that holds up

Multi-factor sign-in with authenticator apps and passkeys, recovery codes for lost phones, and policies you can set per role. A replayed session token kills the whole family of tokens it came from.

An audit trail you can open

Logins, workflow changes and administrative actions are recorded and visible to your own admins inside the product — including our staff’s actions.

We cannot browse your data

Meskora staff have no standing access to your workspace. Support access requires an explicit grant, is limited in scope, and appears in your own audit trail.

Files stay private

Uploads go through our servers into private storage. Your browser and your staff’s phones never hold storage credentials.