Security

Security overview

Mitig8 OS is built as a multi-tenant operations platform for restoration companies. This page summarizes how we approach access and data boundaries. For a formal security questionnaire or MSA, contact sales.

Tenant isolation

Each company runs in its own workspace. Application queries are scoped to the signed-in tenant so jobs, customers, documents, and billing data stay within that company boundary.

Role-based access

Owners, admins, managers, accounting, technicians, and viewers receive module-level read/write permissions. Field shells omit finance; team admin is limited to owners and admins.

Authentication

Users authenticate on the app host (app.mitig8.io). Marketing domains never hold app sessions. Password reset and invites use time-limited links.

Documents & e-sign

Signer links use opaque tokens. Completed envelopes produce PDFs stored in your tenant’s document storage with signing event history for audit.

Operator-managed access

There is no public self-serve signup. Workspaces and users are provisioned by Mitig8 operators, reducing anonymous account creation.

Last updated: August 2026. See also our privacy policy.

Security · Mitig8