Identity federation, role and attribute-based access control, per-tenant envelope encryption, customer-controlled keys, and file-level backup with permission-preserving restore — the control surface every other TeamSync capability inherits from.
Okta, Entra ID, Ping Identity, Auth0, Duo, on-premises Active Directory — TeamSync federates with whichever identity provider the organisation already uses. One IdP configuration covers every TeamSync capability. No per-product identity integration to maintain.
Roles are defined once and inherited across the Intelligent Repository, CLM, eSignatures, eDiscovery, DocuTalk, Workflow Automation, and every other capability. Attribute-based access control layers context-sensitive policies on top — clearance level, jurisdiction, project assignment — for workloads where role alone is not sufficient.
TeamSync-managed keys are the default and are appropriate for most regulated workloads. For sovereign deployments and regulator-mandated key custody, TeamSync supports customer-controlled keys (CMK), bring-your-own-key (BYOK), and hold-your-own-key (HYOK) — where the key never leaves the customer's HSM. Crypto-shred for right-to-erasure is architecturally enforced.
Every version of every document is backed up with the permission state at that point in time. Restore to any prior point in the audit chain. Permission-preserving restore means restored documents inherit the access rules from the recovery point — not the current rules, which may have changed. Cross-region replication and configurable RTO/RPO per support tier.
One permission architecture across every capability. The security review covers the platform once — not once per sub-product. Identity, encryption, and audit chain are architectural constants.
CMK or HYOK means TeamSync cannot decrypt customer content without customer authorisation. The regulator's "what if TeamSync is compromised?" question has an architectural answer.
Crypto-shred executes the right-to-erasure by destroying the key. The content is unreachable — in backups, in archives, in every federated source that the platform manages. Not a deletion queue. Cryptographic erasure.
One permission architecture across records, CLM, eDiscovery, and AI. The security team reviewed the platform once rather than conducting per-product evaluations. Procurement followed the same pattern.
Air-gapped deployment with HYOK key custody. The platform operates on-premise. The key is in the customer's HSM. TeamSync has zero access to the content. The architecture satisfies the sovereignty requirement without custom development.
Patient opt-out triggers crypto-shred across the platform, backups included. The erasure is architectural — no deletion queue, no manual verification, no residual data in backup snapshots.
No pitch deck. We will either show you a clear path forward or tell you we are not the right fit. Bring the toughest question on your desk this week.