Security

Control you can name β€” no compliance theatre

This page describes how access and separation are intended in Pomio. We do not claim ISO certification or other marks that are not on record.

Invite-only

Accounts start with an invitation. There is no open self-signup on the product.

MFA / TOTP

Multifactor with an authenticator app. An administrator can reset without seeing the secret or writing it to the audit log.

RBAC scopes

Rights are not only on or off. Scope own, team or tenant sets the reach of each permission.

Audit

Actions are traceable: who, what, when. Passwords and MFA secrets do not belong in that trail.

Tenant isolation

Tenants share the codebase, not each other’s data. White-label changes name, colour and logo β€” not isolation boundaries.

What you may expect in the log

who Β· what Β· when β€” never passwords / MFA secrets

The audit is meant to reconstruct, not to store credentials.

See Pomio CRM in your own tenant.

Start a 7-day trial, or book a demo meeting with an account manager. This preview site has no purchase flow.