Documentation

Product guides for ComplyNestly customers and their teams.

Security, Privacy & Responsible Use

Security and privacy basics

How your company's data is isolated, who can see what, and how secure links work.

Organization isolation

Every record belongs to exactly one company, and access is enforced at the database level with row-level security. A member of one company cannot read another company's data under any circumstances, regardless of role.

Access within your company

  • Owners and admins see all employees, locations, and company-wide data.
  • Managers see only employees at the locations assigned to them.
  • Manager scoping applies to lists, dashboards, matrix rows, action items, and report totals alike.
  • Employees have no account at all — they access only their own secure portal link.

ComplyNestly issues three kinds of no-login link, all of which are scoped, expiring, and revocable.

  • Secure Credential Profile — a read-only verification view for auditors, GCs, or clients.
  • Employee Portal link — lets one employee submit their own credential documents.
  • Secure renewal link — lets one employee renew one specific credential.

Account hygiene

  • Invite colleagues rather than sharing an account.
  • Grant the manager role by default and reserve admin for people who genuinely configure the system.
  • Remove access promptly when someone leaves the team.
  • Review active share and portal links periodically and revoke stale ones.

Removing a team member's access does not affect employee records; team members and employees are separate concepts.

Related guides