InsTIL — Confidence in ITSubscribe
Trust

Security

How InsTIL Pro is built, in the terms a security reviewer asks about. If something you need is not here, ask — instil-support@precisionit.co.in.

Tenant isolation

Every customer gets their own PostgreSQL database, their own subdomain and their own attachment store. The control-plane database holds only customer and licence records — never ticket, asset or user data. There is no shared application schema in which one customer's rows sit next to another's.

Authentication

Sign-in is by username and password with JWT access and refresh tokens, or by Microsoft Entra ID single sign-on against your own enterprise application. Tokens are validated against your tenant's issuer, not ours. Multi-factor authentication is TOTP-based, with enrolment, verification and recovery flows.

Authorisation

Role-based access control with fine-grained permissions held per role and enforced on both the client and the server. A permission that is missing server-side is denied regardless of what the interface offers.

Directory integration

Users can be synchronised from Active Directory or LDAP on a schedule, from the organisational units you choose, so joiners and leavers follow your existing process rather than a second one.

Audit

User actions and application events are written to audit tables. Ticket state changes are recorded in an immutable ticket log, so who did what and when is answerable after the fact.

Deployment options

If your data may not leave your network, the whole stack runs in containers inside your perimeter behind your own reverse proxy. The cloud and on-premises builds are the same application.

Security review, certifications and data residency

Procurement teams usually need more than a page. Ask us for our current certification position, the regions a workspace can be hosted in, our retention and deletion policy, and a completed security questionnaire — we will send them to a named contact at your organisation.

instil-support@precisionit.co.in