Security

Built for teams that can't take chances with incident data

Root cause investigations often contain the details a company is least eager to see leave the building. Here's how GuidedRCA handles that.

Tenant isolation, enforced at the database

Every tenant is isolated with PostgreSQL row-level security, not just filtered in application code — the database itself refuses to return another tenant’s rows.

Role-based access control

Permissions are granted as strings (module.action) with wildcard support, so a role can be scoped to exactly what it needs — investigator, admin, or platform-wide.

Authentication built on standards

JWT access tokens with refresh-token rotation, and passwords hashed with bcrypt. No custom crypto, no plaintext credentials.

Cloud or on-premises

Run GuidedRCA in our cloud, or deploy it entirely inside your own network. Incident data never has to leave your infrastructure if your policy requires that.

An audit trail by construction

Every investigation moves through the same 8 stages and produces the same 12-section report — so what happened to a finding is always reconstructable, not just remembered.

Versioned methodology

Questionnaire sections, categories and templates are versioned centrally per tenant, so a change to your investigation methodology is tracked, not silently overwritten.

Deployment

Your data, your infrastructure, your call

Most incident-investigation data is sensitive by nature. GuidedRCA doesn't force a single hosting model on you.

Cloud

Fully managed — we run the database, the backend and updates. You get a URL and a login.

On-premises

Runs inside your own network on infrastructure you control. Updates are delivered as versioned releases you apply on your schedule.

Have a specific security or compliance question?

Tell us about your requirements and we'll walk through exactly how GuidedRCA fits.