Two-step sign-in

Every account sets up a second step on first sign-in: an authenticator app or a code by text message. Sessions expire and are refreshed per device; too many failed attempts lock the account for a while.

Roles that match the room

View only, staff, manager and admin within an organisation. Staff receive, move and use stock; managers approve orders, write off stock and action recalls; admins keep users and integrations. Platform staff see every organisation; an organisation sees only its own.

One organisation's data apart from another's

Every record belongs to an organisation and every request is checked against it on the server, not just in the screen. Public identifiers are random, never a counting number.

A ledger that is never edited

Stock movements are only ever added. The database refuses to change one. Every write to a catalogue record is logged with who, when, from where, and what changed.

Keys and secrets shown once

API keys are stored as a hash and shown once when made; a lost key is revoked and replaced. Webhook messages are signed with a secret only the receiver knows. Nothing secret lives in the code.

Careful on the way out

Outbound calls, to vendors' email, to webhooks and to the photo reader, go only to addresses the deployment allows: public https hosts, never a private network. Passwords are checked against known breaches without the password leaving the server.

What is logged

LogWhat it holdsWho reads it
ActivityEvery change to a record: who, when, from where, what changed, and the request and answer.The organisation's admin and platform staff
Sign-inEvery sign-in attempt and its outcome, per device.Platform admins
RefusalsEvery request refused for lack of permission, and why.Platform admins
MovementsEvery unit of stock received, moved, used, counted, held, released or written off.Everyone in the organisation

Questions a security review asks

Where is the data?

In your deployment's database, in the region you choose. Armaria is deployed per customer or per group; nothing is shared between deployments.

What leaves the server?

Emails and text messages you asked for, webhook messages to addresses you named, and, if you switch it on, photos for identification. Nothing else.

Can we export it?

Everything the screens show is available through the API, in JSON, with a read key.

How are dependencies kept safe?

Every build scans its packages for known advisories and fails on a high or critical one. Static analysis runs on every change.

Need the detail?

Ask for the security overview and we will go through it with your IT team.

Contact us