Data protection that starts at the database engine.
EnaSmartWay is engineered for regulated industries. Every security and compliance property is a structural design decision — not a post-launch configuration.
Security Pillars
Six layers of protection.
PostgreSQL RLS
Row-Level Security policies enforced at the database engine. Every query scoped to the current tenant UUID via session variable. Cross-tenant leakage is structurally impossible.
OIDC via EnaCore Identity
Admin authentication through an enterprise OIDC provider with PKCE. No passwords in EnaSmartWay. Short-lived access tokens with Redis session store.
HMAC-SHA256 Audit
Immutable, append-only audit log with cryptographic hash chaining. Retained 3–7 years by plan tier. Chain verified on demand.
Encrypted Secrets
Webhook signing secrets, SMS provider credentials, and session data encrypted with AES-GCM before storage. Keys managed via environment, never in source code.
KVKK & GDPR Consent
Configurable consent on visitor-facing wayfinding flows. Explicit consent recorded where contact details are captured. PII fields masked before AI processing.
Per-tenant Object Storage
Visitor media uploads (photos, voice, video) stored in per-organization Huawei OBS buckets with encryption at rest.
Security FAQ
See EnaSmartWay in your building.
Contact us — we’ll walk through space modeling, QR points, route building, and your enterprise configuration together.