Vistentry
Request a Demo
Security & trust

Security is the product, not a feature bolted on.

Vistentry is built for enterprise reception and security teams who need to know exactly who has access to their buildings, and exactly who has access to that data.

Architecture

How isolation and access actually work

Real tenant isolation, enforced by the database

Every tenant's data is isolated with Postgres row-level security, not application-layer filtering alone. A query for one tenant cannot return another tenant's rows, even if the application code above it has a bug.

Role-based access control

Every permission a user has is explicit and auditable. Custom roles are scoped to exactly the actions they need, and every permission change is itself a logged action.

Access cards tied to a single visit

Physical access credentials are issued per visit, not per person indefinitely. Access is revoked automatically the moment a visit ends, no manual deprovisioning to forget.

Watchlist screening at check-in

Every visitor is screened against your organization's watchlist automatically, before host approval clears. Matches are held for a real human decision, never silently waved through.

Auditability

Everything that happens is recorded, and reviewable

  • Every state-changing action (visit approval, security hold, card issuance, role grant) is written to an append-only audit log, not just the current row's state.
  • Platform-side actions (tenant lifecycle changes, plan edits, support access grants) are logged separately from tenant activity, with a full cross-tenant view available to platform administrators.
  • Support access to a tenant's data by Bluevertex staff requires an explicit, approved, time-boxed grant. Nobody, including platform administrators, reads tenant visitor data without one.

Have a security questionnaire?

Talk to us directly about your specific requirements, we'd rather answer real questions than publish a generic checklist.

Contact us