Trust and security

Security Overview

Last updated: July 8, 2026

Sorbtree is designed for organizations that need records, workflows, automations, decisions, and workload activity to remain controlled, explainable, and traceable.

Security overview, not a certification: this page describes Sorbtree's security approach at a high level. Specific controls, responsibilities, service levels, and commitments are defined in the applicable customer agreement, deployment documentation, and security schedule.

1. Security approach

Sorbtree treats security as part of the operating model rather than a separate layer added after implementation. Records, authorizations, workflows, automations, lifecycle transitions, configuration changes, and administrative activity are designed to operate within explicit controls and traceable boundaries.

Least-privilege access

Give users and administrators only the access required for their responsibilities.

Governed change

Make important configuration changes reviewable, attributable, and reversible.

Traceable operations

Keep records, work, decisions, automation activity, and history connected.

Deployment choice

Support different sovereignty, isolation, and infrastructure requirements.

2. Platform controls

Depending on the deployment and licensed configuration, Sorbtree may support controls such as:

  • role- and group-based authorization;
  • organization, record-type, dashboard, queue, and operational access boundaries;
  • conditional field, form, tab, and action behaviour;
  • controlled lifecycle states and permitted transitions;
  • validation and business rules that prevent incomplete or invalid processing;
  • work queues, assignment, pull-back, and ownership controls;
  • configuration versioning, review, approval, publication, and rollback patterns;
  • activity histories and evidence supporting operational accountability; and
  • separation of reusable automations from end-to-end workflow orchestration.

3. Secure engineering

Sorbtree's engineering approach is intended to include security considerations throughout design, implementation, review, deployment, and maintenance. Practices may include dependency management, code review, environment separation, controlled secrets, input validation, authorization checks, database migration discipline, backup planning, and release verification.

Security requirements can vary materially between hosted, dedicated, customer-hosted, and air-gapped environments. Detailed architecture and implementation controls are addressed during solution design and security review.

4. Operational security

For environments operated by Sorbtree, operational safeguards are intended to address administrative access, monitoring, logging, backup, restoration, change management, incident handling, and infrastructure maintenance. Exact practices and responsibilities depend on the service and agreement.

Sorbtree does not claim that any system is invulnerable. Security is an ongoing process that requires maintenance, timely updates, appropriate configuration, and cooperation between Sorbtree, customers, hosting providers, and implementation teams.

5. Deployment models

Canadian cloud

A Sorbtree-operated hosted option designed around Canadian residency priorities.

Dedicated cloud

An isolated environment for customers requiring stronger tenancy boundaries.

Customer-hosted

Deployment on customer-approved infrastructure, with responsibilities allocated by agreement.

Air-gapped or restricted

A deployment pattern for sensitive environments where external connectivity is limited.

The selected deployment model affects infrastructure ownership, administrative access, monitoring, patching, backup, recovery, network security, and incident-response responsibilities.

6. Shared responsibility

Customers are responsible for using Sorbtree securely, including managing users and groups, protecting credentials, reviewing permissions, configuring retention and business rules, securing customer-managed devices and networks, approving integrations, and ensuring that workflows and automations are appropriate for their use case.

For customer-hosted or air-gapped environments, the customer is generally responsible for infrastructure security, network controls, operating systems, backups, monitoring, availability, disaster recovery, and timely installation of provided updates unless otherwise agreed.

7. Security incidents and vulnerabilities

Sorbtree investigates reported security concerns and coordinates response according to the affected environment, contractual commitments, and available evidence. Customers should promptly report suspected unauthorized access, credential compromise, vulnerabilities, or misuse involving Sorbtree.

Do not include sensitive customer data, exploit code, or personal information in an initial email. Sorbtree will coordinate a safer method of exchanging details where needed.

8. Reviews and assurance

Sorbtree can participate in reasonable customer security, privacy, architecture, and deployment reviews. Available evidence and documentation may depend on product maturity, deployment model, confidentiality requirements, and the applicable commercial arrangement.

Any reference to security practices on this page should not be interpreted as a representation that Sorbtree currently holds a particular certification or attestation unless Sorbtree confirms that status in writing.

9. Contact

Report a security concern
security@sorbtree.ca