Live posture unavailable — set NEXT_PUBLIC_GTM_API_BASE to load SSO/RBAC flags from staging or production.
Identity & access
Do you support enterprise SSO (SAML/OIDC)?
Staff authentication supports Nest password, Keycloak OIDC, or dual mode (STAFF_AUTH_MODE). SAML/OIDC via Keycloak is available when PTT_STAFF_KEYCLOAK_ISSUER is configured. The live posture panel shows the current mode for this deployment.
Is MFA enforced?
OTP MFA is required for positions listed in STAFF_MFA_REQUIRED_POSITIONS (default: GDKD and super-admin). Other roles follow your IdP policy when SSO is enabled.
Can IT use Permission Sets instead of editing the full matrix?
Yes — Permission Sets are available on the staff RBAC admin path when PostgreSQL staff is enabled. Sets bundle section caps and can be assigned per user.
Do you support row-level lead scope?
Client/workspace scope for leads is available when STAFF_SCOPE_PILOT=1. This is a pilot capability for agency multi-client deployments — not a substitute for full ABAC.
Data protection
Where is production data hosted?
Singapore (AWS ap-southeast-1) unless contractually agreed otherwise. See Trust Center → Data residency.
Do you offer a DPA and SCCs for EU/UK?
Yes — /en/legal/dpa and sub-processor DPAs (AWS, Stripe). SCCs apply per vendor DPA where data leaves the EEA.
Is data encrypted in transit?
TLS 1.2+ for all public and staff paths. Object storage and database use provider encryption at rest.
Compliance & audit
SOC 2 status?
SOC 2 Type I is in progress. A report link appears on the Trust Center only after PO and auditor sign-off — never before.
Can we export audit logs?
Staff RBAC and GTM actions are audit-logged. Enterprise access-review ZIP export is on the WIN roadmap; contact sales for current export options on your contract tier.
Availability
What is your uptime commitment?
99.9% monthly target for marketing site, demo API, and public CMS read. See /en/status for live component health and incident history (published only after measured production days).