Platform · Security
Control Who Sees What,
Down to the Last Permission
Assign a ready-made access profile or build your own from 125 individual rights. Lock external suppliers and clients to their own data, gate the editor to review-only, and sign in through SSO with MFA. Every action is logged.
The Access Toolkit
One Model for Everyone Who Touches a Project
Inhouse staff, external suppliers, and clients all live under the same permission system, scoped to exactly what each person needs to see and do.
Predefined Access Profiles
Eleven ready-made profiles across inhouse, supplier, and client roles, from Administrator and Manager down to External Worker (Limited). Assign one and the user inherits the right defaults.
125 Granular Rights
Each inhouse profile is built from up to 125 individual access rights. Toggle navigation, project access, resources, finance visibility, and user management one permission at a time.
Custom Profiles
Need a PM without finance access or a client reviewer with editor rights? Start from any template, adjust the permissions, and save a custom profile that fits your team.
Review-Only Access
A dedicated right turns the editor into a read, comment, and status-change workspace. Reviewers can flag issues and move segments forward but cannot alter source or target text.
External Isolation
Suppliers and clients see only their own company, projects, and jobs, never your other accounts or internal data. The same boundary applies whether they work in the editor or the portal.
SSO and MFA
Sign in through SAML 2.0 single sign-on with Microsoft Entra ID, Okta, or ADFS. Enforce multi-factor authentication platform-wide, alongside password, session, and IP policies.
Accountability
Every Action, on the Record
The activity log captures sign-ins, project and settings changes, file uploads and downloads, API access, and job assignments. Filter by user, date range, event type, or affected object, and export the log for your own audit and compliance archives. When a security review asks who changed what and when, the answer is one filter away.
- Logins, settings changes, file transfers, and API calls all recorded
- Filter by user, date range, event type, or affected object
- Export for external analysis or long-term archival
- API access inherits the user profile and tokens expire after 30 minutes
- 09:12Jane DoeSigned in
- 09:14Jane DoeUploaded source.xliff
- 09:15systemAPI export · /v1/jobs
- 09:18Max MustermannStatus → Delivered
Security and Compliance
A Security Posture Built for Procurement Review
Independently certified, EU- or US-hosted, and documented end to end, so your security and IT teams can complete a vendor assessment without chasing answers.
Information Security
ISO 27001 certified ISMSAES-256 at restTLS 1.2+ in transit3rd-party penetration testing · NDA summaryEncrypted automated backupsData Privacy
GDPR compliantSigned Data Processing AgreementSub-processor list · DPA annexData residency · EU or USSingle-tenant hosting · enterprise72-hour breach notificationAccess Control
SAML 2.0 SSO · Entra ID, Okta, ADFSMFA enforceable platform-wide125 access rights per profileCustom profiles · project & resource scopeOperational Resilience
Activity log · filterable & exportableDocumented incident responseISO 27001 facilities · EU & USPassword policies, timeouts, IP limits
Common Questions
What Teams Ask About Security
See How Your Roles Map to Wordbee
Talk through access profiles, SSO, and the activity log with our team, or start a free trial and configure them yourself.