Role-based Multidimensional access control
Granular permissions by role, business unit and module, configured to match your org structure.
Role-based multidimensional access control, multi-factor authentication, encryption and full audit trails - by default, on every module, not as a premium add-on. procurEngine is ISO 27001 and ISO 27701 certified, independently audited.
Granular permissions by role, business unit and module, configured to match your org structure.
MFA supported natively, alongside SSO integration with your identity provider.
Every action, approval and change is logged, timestamped and attributable. Retention and export options are covered in the security pack.
Encrypted in transit and at rest throughout the platform. Protocols, ciphers and key management are detailed in the security pack.
Residency for your deployment is confirmed during evaluation and set out in your contract.
Detailed security and compliance documentation shared during evaluation, under NDA where required.
Specifics are shared with evaluation teams under NDA rather than published, so that what governs your deployment is the detail in your agreement. The pack covers the standard questionnaire ground:
Incident response, access control and the rest of the above sit within our ISO/IEC 27001:2022 certified ISMS and are independently audited as part of that certification - see our certifications.
Stated plainly, so an evaluation team can establish our posture from this page rather than waiting on a sales conversation.
Information Security Management System (ISMS), certified by Intertek Certification Limited, a UKAS-accredited certification body. Scope: the ISMS at AgileApt Solutions Private Limited (Noida, India), applying to the application development, maintenance and support of procurEngine (SaaS), supported by IT, HR, Admin, Legal, Sales and Marketing. Certified since June 2025 and valid to June 2028, subject to Intertek's ongoing surveillance.
Privacy Information Management System (PIMS), certified by Intertek as an extension to our ISO/IEC 27001:2022 certification and valid in combination with it. Same entity and product scope, with AgileApt Solutions acting as both PII Controller and PII Processor. Certified since June 2025 and valid to June 2028.
A SOC 2 examination is underway. Report type and target completion date are shared with evaluation teams on request.
Neither is a certification scheme, so no vendor can hold a certificate against them. Our ISO 27701-certified PIMS underpins our GDPR and DPDP compliance programmes, which are ongoing.
Both ISO certifications are described in full on our certifications page. Certificates, certificate numbers and audit documentation are shared on request during evaluation, under NDA where required, and Intertek certificate validity can be confirmed directly with Intertek.
Talk to us for detailed security and compliance documentation as part of your evaluation.