Paragon Environmental Solutions Ltd

Data Security Overview

Client information is accessible only to authorised users assigned to the relevant organisation, location, role and asset group.

Tenant separation

Every record is bound to a client organisation. Database-level row security policies are evaluated on every read and write, so a signed-in user can only reach records belonging to their own organisation. Paragon Environmental Solutions Ltd staff roles have controlled cross-organisation access for delivery and review purposes, and that access is logged.

Encryption

All traffic is encrypted in transit. Documents, photographs and reports are stored in private storage that is not publicly addressable; files are served through short-lived authorised links only.

Access control

Permissions are role-based and can be narrowed further by site, location and asset group. Invitations are time limited, access periods can be set to expire, and accounts can be revoked immediately.

Audit logging

Sign-in events, record changes, report issue and administrative actions are written to an append-only audit log associated with the acting user and organisation.

Report distribution

Reports are released only after technical review and are visible only to users whose role permits report access within the owning organisation.

This document relates to the Paragon Digital Asset Integrity Platform only and contains no client-confidential information. Last reviewed 10 August 2026.