Resources
Security
How Ikonic keeps your business data isolated, encrypted, and auditable — by design, not as an add-on.
Last updated: July 2026
Tenant isolation
Ikonic is multi-tenant by design. Every record is scoped to a tenant and legal entity, and those filters are enforced in the data layer — so a query can never accidentally cross a tenant boundary. Soft-delete is enforced the same way.
Encryption
Data is encrypted in transit (TLS) between your browser, our services, and our sub-processors. Sensitive fields and credentials are protected at rest with managed keys.
Access control
Role-based access and owner-scoped visibility (My / Team / All) mean users only see what they should. Access decisions fail closed — when scope is uncertain, access is denied, not granted.
Audit trail
Every soft-deletable entity carries a full audit history: who changed what, and when. This trail is consistent across all modules and backs both compliance and incident investigation.
Payments & PCI
Card data is handled by PCI-compliant payment gateways and vaulted tokens — Ikonic never stores raw card numbers. Over-collection guards and settlement-to-GL reconciliation protect the money trail.
AI data handling
AI agents operate on tenant-scoped knowledge only. We do not use your business content to train third-party models without your explicit instruction, and tool execution is sandboxed.
Data residency & export
Your data belongs to you. You can export your records at any time, and we support regional data-residency requirements for customers who need them.
Report a vulnerability
If you believe you have found a security issue, please contact us at info@ikonicsys.com. We investigate every report and respond promptly.
