CMIT Auto

Security

Security you can explain to your clients.

Built for MSPs who answer security questionnaires every week. Every control is auditable, documentable, and real.

Zero-Trust Architecture

No admin action auto-executes. Every elevated and critical action requires explicit human approval through a verified channel.

3-Tier Approval System

Standard (automated), Elevated (senior tech approval), Critical (franchise owner + MFA + typed confirmation). Color-coded across every screen.

AES-256-GCM Credential Delivery

Credentials delivered via one-time encrypted links with 15-minute expiry and automatic destruction after access.

Triple Audit Trail

Every action logged to local database, Autotask ticket notes, and IT Glue documentation — simultaneously. Nothing is lost.

5-Stage Email Security Pipeline

SPF/DKIM/DMARC validation, sender verification, content analysis, injection detection, and risk scoring before any workflow triggers.

Local AI Classification

Ollama runs on-premise. No ticket data sent to cloud LLM providers. Your client data stays on your infrastructure.

Per-Franchise Isolation

PostgreSQL Row-Level Security provides hard database isolation. Each franchise's data is cryptographically separated.

HMAC Request Signing

All API requests are signed with HMAC-SHA256 to prevent tampering and replay attacks.

Security

Zero-trust isn't a buzzword. It's our architecture.

No admin action auto-executes. Ever.

Tier 3: Critical

9 workflows

Owner approval + MFA + typed confirmation

Tier 2: Elevated

15 workflows

Requires senior tech approval

Tier 1: Standard

19 workflows

Fully automated — no approval needed

Need more detail?

Security whitepaper available on request. Contact us for a full architecture review or to schedule a security walkthrough with your team.