Resources

Security

How Ikonic keeps your business data isolated, encrypted, and auditable — by design, not as an add-on.

Last updated: July 2026

Tenant isolation

Ikonic is multi-tenant by design. Every record is scoped to a tenant and legal entity, and those filters are enforced in the data layer — so a query can never accidentally cross a tenant boundary. Soft-delete is enforced the same way.

Encryption

Data is encrypted in transit (TLS) between your browser, our services, and our sub-processors. Sensitive fields and credentials are protected at rest with managed keys.

Access control

Role-based access and owner-scoped visibility (My / Team / All) mean users only see what they should. Access decisions fail closed — when scope is uncertain, access is denied, not granted.

Audit trail

Every soft-deletable entity carries a full audit history: who changed what, and when. This trail is consistent across all modules and backs both compliance and incident investigation.

Payments & PCI

Card data is handled by PCI-compliant payment gateways and vaulted tokens — Ikonic never stores raw card numbers. Over-collection guards and settlement-to-GL reconciliation protect the money trail.

AI data handling

AI agents operate on tenant-scoped knowledge only. We do not use your business content to train third-party models without your explicit instruction, and tool execution is sandboxed.

Data residency & export

Your data belongs to you. You can export your records at any time, and we support regional data-residency requirements for customers who need them.

Report a vulnerability

If you believe you have found a security issue, please contact us at info@ikonicsys.com. We investigate every report and respond promptly.