Efixera

Trust Center

Your data, your infrastructure, one access model.

Efixera is built for an organization that handles confidential contracts, controlled documents, and personal files. This page sets out how access and confidentiality work, who owns the data and how it leaves, what the audit trail records, and how the platform is hosted — single-tenant and on-premise, built to serve ISO 9001/IMS and ISO/IEC 17025.

Access & confidentiality

One identity model governs every module

Access is declared once in Efixera Core and inherited by every module — so confidentiality is enforced the same way everywhere, not reinvented per tool.

One access model, not five

A single SSO login and one RBAC role model govern every module. Access is declared once in Efixera Core, not re-implemented per tool — so a person who leaves loses access everywhere at once.

Per-object confidentiality

Confidential records (the IMS document base, personal files, sensitive contracts) carry object-level access control. A folder being visible does not make its contents readable.

Least-privilege by default

Roles map to job function. Org-scoping limits each user to the units they are responsible for, so a reviewer in one department never sees another's confidential work.

Hardened sign-in

Two-factor authentication for e-signature actions, encrypted secrets at rest, recovery codes, and brute-force rate-limiting on login and signing — admins can force a 2FA re-enrolment when a device is lost.

Data ownership & export

The organization owns its data — and can take it out

A platform you can leave is one worth staying on. Efixera is single-tenant, runs on infrastructure you control, and exports in open formats.

Status quo
With Efixera
Data lives inside a vendor's cloud you don't control
The organization owns its data; the platform runs on infrastructure you control (on-premise or a dedicated install)
Leaving means a costly export project — or losing history
Built-in Excel / PDF / CSV export across every module; your records leave in open formats, not a proprietary dump
Each point tool holds a slice of the record hostage
One data layer holds the whole record — a project, its documents, its quality events, and its people linked natively
Upgrades and access changes depend on a vendor's schedule
A single-tenant install per organization — your environment is upgraded and configured on your terms

Audit trail

Who changed what, when — answered by the record, not by memory

The audit-trail gap is the one Efixera was built to close: status, versions, and approvals are traceable on every record.

Append-only history

Every consequential action is written to an audit log that records who did what, when. Entries are added, never silently overwritten.

Versioned documents

The file store keeps revision history with integrity, so the current version and every prior one are recoverable and attributable — the document-control answer to "is this the latest?".

Traceable approvals

MOC, non-conformance, leave, and DCC release all run on one approval-workflow engine, so each decision carries its route, its approvers, and its timestamps.

Electronic signatures

Release and sign-off actions are bound to a verified identity, giving audit-ready evidence of who authorized a controlled document.

Hosting & sovereignty

Single-tenant, on-premise, with an enforced AI boundary

Efixera is delivered as a dedicated install per organization. Confidential documents stay inside your environment — including when AI features process them.

Dedicated install

No shared multi-tenant database. Each organization gets its own environment, upgraded and configured on its own terms.

On-premise by default

Designed to run on infrastructure you control, so sensitive records never have to leave the perimeter to be useful.

Sovereign AI gate

Controlled documents are processed only by an on-premise model. External AI is limited to explicitly non-confidential use — the split is enforced, not optional.

Detailed deployment and security particulars are shared under NDA during a walkthrough.

Standards alignment

Built to serve the standards an organization is audited against

Efixera does not replace your management system — it gives it an auditable spine.

ISO 9001 / IMS

Document control with versioning, normative-document validity tracking (expired vs active), risk management, Management of Change, and non-conformance — the records an IMS audit asks to see, kept current.

ISO/IEC 17025

Equipment and calibration registers with due-date tracking, accreditation documents, and environmental (temperature/humidity) monitoring — traceability for a testing or metrology laboratory.

Trust FAQ

Common questions from IT and Quality leads

Where is the data hosted?+

Efixera is delivered as a single-tenant, dedicated install per organization, designed to run on infrastructure you control — on-premise or a private environment. There is no shared multi-tenant database holding several organizations' records together.

Do you use external AI services on our documents?+

AI features run through a pluggable provider with an enforced split: confidential controlled documents are processed only by an on-premise model inside your environment, never sent to an external service. An online provider is available only for explicitly non-confidential, demo use — the gate enforces the boundary, it is not a setting to forget.

Who owns the data, and can we get it out?+

The organization owns its data. Every module supports Excel / PDF / CSV export, so records and registers leave in open formats. The platform is built to avoid lock-in by design.

What standards does the platform serve?+

Efixera is built to support audit-readiness for ISO 9001 / IMS and ISO/IEC 17025 (laboratory/metrology) — through document control, normative-document validity tracking, calibration registers, risk, MOC, and non-conformance. These are capabilities that serve those standards; specific certifications of any deployment are confirmed per organization.

How is access removed when someone leaves?+

Because access is governed by one identity model in Efixera Core, disabling a user removes their access across every module at once — there is no per-tool cleanup to chase.