Company-domain sign-in
Google sign-in can be restricted to the configured company domain. User deactivation prevents future access, while historical records remain available.
Understand who can access the work, what information is collected, and how operational evidence is recorded. Trust starts with specifics.
IssueLane connects sensitive operational information with the people responsible for it. These controls are implemented in the product; deployment configuration, hosting, and integration choices determine how they operate for your organization.
Google sign-in can be restricted to the configured company domain. User deactivation prevents future access, while historical records remain available.
Employee, department, and administrator permissions control access to requests and operational records. Server-side checks enforce permissions on protected actions.
Attachment downloads require authorization. Supported uploads are validated, and S3-backed downloads can use time-limited signed URLs.
The device privacy page describes collected information from the served query pack. Supported usage collection can be disabled through device settings.
AWS and GitHub integrations use read-only external access. Device agents use per-device credentials with rotation. API keys support controlled custom connections.
Ticket histories and audit records capture actions and decisions. Access reviews, offboarding records, and reports contribute to evidence gathering.
Export evidence for 13 selected controls mapped in the product to SOC 2 and ISO 27001 references. Bring device checks, access reviews, offboarding, and security findings into a printable report and CSV exports.
These mappings support audit preparation. They do not establish certification or complete coverage of either framework.
Discuss your hosting requirements, data handling, access model, and integration scope during the demo. Confirm support, retention, and deployment commitments for your organization before rollout.
AI-assisted triage and invoice extraction include review steps. When enabled, the relevant input is processed by the configured AI provider.
Device findings support monitoring and tracked follow-up. They do not imply remote wipe, automatic patching, or inspection of every AI connection.
Bring employee support, assets, and operational follow-up into one workspace—with a clear owner for every next step.