What is actually implemented, stated plainly

This page describes controls that exist in NDT Link today and clearly labels what does not. We do not claim certifications, penetration-test results, encryption specifics, data residency, backup objectives, or uptime guarantees without supporting evidence.

Implemented controls

Verified accounts only

The application area requires a signed-in account; no inspection data is shown on the public website.

Role-based permissions

Users are invited by administrators with admin or user roles; administrative actions require an admin account.

Tenant-scoped data separation

Each organization's business records are scoped to that tenant, so one company's records are not visible to another's users.

Controlled report status

Reports move through draft, submitted, under review, approved, and delivered — only approved reports are released.

Audit history

Workflow actions — creations, status changes, assignments, approvals, deliveries — are recorded with user and timestamp.

Recorded approval identity

Approvals record the signature entry, reviewer, and dates on the report.

Hosted platform

NDT Link runs on the Base44 platform, which manages hosting, accounts, and authentication. Backup and recovery specifics are available on request.

Not yet implemented or not claimed

  • Granular per-entity permission configuration beyond the current admin/user roles
  • Direct external customer login accounts for the customer portal
  • Formal data-export tooling (records can be reviewed and transcribed today; export is planned)
  • Independent security audits or certifications — none are claimed on this page

If a specific control matters to your procurement process, ask us directly through the contact form — you will get a straight answer about what exists today and what is on the roadmap.

Discuss your security requirements

Bring your access-control and audit requirements to the demonstration and we will address each one against the current implementation.

Request a Demo