ParleHub
Start free
Security Pricing Blog Sign in
Security & compliance

Your data. Your tenant. Your rules.

ParleHub is built so an IT admin can say yes: sign-in through the identity provider you already run, files that stay inside your own Microsoft 365 or Google Workspace tenant, and a record of who did what that nobody — including us — can quietly edit.

Identity

Sign in the way your org already does

Enterprise SSO means one fewer password to manage and one fewer account to deprovision when someone leaves.

  • check_circle Microsoft Entra ID single sign-on
  • check_circle Google Workspace single sign-on
  • check_circle Auto-provisioning by verified email domain — no manual account creation
  • check_circle Org admins can require SSO and lock out password login entirely
Screenshot of ParleHub's organization sign-in settings, showing Microsoft Entra ID and Google Workspace SSO configured with SSO enforcement enabled
Screenshot of ParleHub's organization file storage settings, showing SharePoint (Microsoft 365) connected as the document library so project files stay in the organization's own Microsoft 365 tenant
Storage

Files that never leave your tenant

Point a project at storage you already control instead of trusting another vendor with your documents.

  • check_circle SharePoint (Microsoft 365) as project storage
  • check_circle Google Drive (Shared Drives) as project storage
  • check_circle Least-privilege access — scoped to the specific site or drive a project connects, not your whole tenant
  • check_circle Prefer a fully managed option? ParleHub Cloud storage is available on every tier
Access control

Roles that match how orgs are actually run

Clear app roles roles, no flat, all-or-nothing admin switch.

Org Admin Organization setup, Create and manage projects
Project Admin Manage a project & its members
Project Member Chat, share, use project files
Audit trail

A ledger nobody can quietly edit

Every sensitive action — sign-ins, membership changes, budget edits, SSO configuration, model and storage changes — is written to an append-only audit log.

  • check_circle Append-only enforcement at the core level, no app overrides
  • check_circle Even a compromised admin credential can't rewrite or delete history
  • check_circle Covers sign-ins, role & membership changes, budget edits, and SSO / model / storage configuration
Audit ledger lockAppend-only
#00482 member.role.changed sha·9f3c…
#00481 budget.updated sha·1a7e…
#00480 sso.enforcement.enabled sha·c42b…
#00479 storage.connected sha·77d0…
#00478 member.invited sha·e5b9…

Rows are only ever appended. UPDATE and DELETE are blocked by a database trigger — each entry is hash-chained to the one before it, so any tampering is evident.

Platform hardening

The details you'd ask about in a security review

speed

Denial-of-wallet protection

Rate limiting and bounded agent tool-call loops prevent runaway spend from a stuck agent.

key

Two-vault secret broker

Your provider keys are stored securely so a single compromised credential can't expose every customer's keys.

verified_user

Managed-identity-first Azure auth

Minimal long-lived static secrets across SQL, Blob Storage, and Key Vault.

shield

CSP, HSTS & secure cookies

Baseline security headers enforced on every request.

Ready to bring this to your admins?

Start free at app.parlehub.com arrow_forward