We built Actinode HQ to run the financial and operational core of your consultancy. That means client invoices, consultant payments, tax details, and people's personal information all live inside it. We take that responsibility seriously, and this page explains, plainly, how we protect it.
// ACCESS CONTROL
Every person in your workspace gets exactly the access their role requires, nothing more.
Full control of the workspace, including billing and settings.
Same operational access as Owner, without subscription control.
Manages assigned projects and consultants, read only on invoices.
Handles client invoicing only, no visibility into consultant pay or margins.
Logs time and sees only their own assigned projects.
External, read only access to their own project status and invoices.
This isn't a marketing description. It's a live permission system, checked on every action, and it's viewable in full detail from inside the app.
Personal identity fields such as PAN, Aadhaar, passport, and bank account details are masked by default. They only appear when someone deliberately reveals them, and only the person they belong to can edit their own sensitive fields. Role and employment data stays under admin control, so no one can quietly change their own pay grade or title.
Our platform team can enter a workspace to help with support, the same way any SaaS provider occasionally needs to. When that happens, it's never invisible. A persistent on screen indicator shows the workspace that someone from our team is inside, and every platform level action is written to a permanent, append only audit log.
Most software tells you what your role can do in a help article that goes stale the moment something changes. We built a live Permissions Matrix instead. It's generated directly from the running configuration, not a document someone forgot to update, so what you see is always what's actually enforced.
If you connect Actinode HQ to other tools, or use our Claude MCP integration to log time or query hours from a conversation, that access runs through workspace scoped API keys. Keys can be issued per person, revoked at any time, and every key operation is logged.
// STATUS
We're a young platform, and we'd rather tell you that plainly than overstate where we are. We don't yet hold formal certifications like SOC 2 or ISO 27001. We're building toward them as the platform and our customer base grow, and we'll update this page the moment that changes. If you have specific security or compliance questions before a demo, ask us directly. We'd rather have that conversation early than have you find out the answer isn't what you needed after you've already signed up.