Back to technical overview

Technical transparency

Security principles
High level, no fog.

This page explains the key security principles in TapInn at a high level: authentication, access, tenant-separated data and controlled exposure of features.

Authentication

Web and mobile use different but coordinated auth patterns suited to each surface.

Access

Role and tenant boundaries are not cosmetic; they must be enforced in both the UI and the API.

Controls

Rate limiting, audit trails and error reporting are used to reduce misuse and provide traceability.

Details

Explained in practice.

Role-based access

Employees and administrators have different areas of responsibility and should not see or be able to do the same things.

Tenant isolation

Customer data must be isolated per tenant. This applies to reading, updating and side effects in the system alike.

Module gating

If a feature is not activated in the workspace settings, it should not just be hidden visually. The APIs and related surfaces must also stop in a controlled way.

Defence in depth

The goal is not to rely blindly on one layer. UI, auth, role lookups and data filtering should together build a clear security boundary.

Contact

Need a concrete answer?

If you are evaluating TapInn or need clarification on workflow, privacy or technical frameworks, you can contact us directly.

hei@tapinn.no