Trust

Data Security

This page describes the security controls My PG OS provides for tenant, staff, and business data.

Role-based access

Every action is gated by the user's role. Tenants, staff, branch admins, super admins, and developers see only what they need.

Branch-wise access

Data is scoped to the branch a user belongs to. Branch admins cannot see other branches' data unless they are the super admin.

Private document storage

Government ID files and KYC documents are stored privately. Only authorised admins can view them.

Admin approval

New tenant accounts unlock only after admin approval, preventing unauthorised access.

Secure login

Google login is used for tenants. Admin and staff accounts use platform-managed credentials with secure session handling.

No WiFi password in WhatsApp

Sensitive information like WiFi credentials is shown inside the Tenant App rather than sent over WhatsApp, where it could be forwarded.

Sensitive data controls

Access to sensitive operations such as deletes, KYC viewing, and bulk exports is restricted and logged.