Enterprise access control, built in
Every action is scoped by role and isolated by tenant. Give resellers and clients exactly what they need — nothing more — and keep a complete audit trail.
The right access for every person
Four roles — superadmin, reseller, client and staff — map to a clear permission model, and tenant isolation is enforced at the data layer, not just hidden in the UI.
- Role-based access: superadmin, reseller, client, staff
- Tenant isolation enforced at the database layer
- Per-reseller scoping to their own clients
- A complete, searchable audit log
Secure by default
Two-factor authentication, encrypted credentials, device blocking and HMAC-signed webhooks keep both the platform and your network protected.
- Two-factor authentication (TOTP)
- Encrypted secrets — never shown in plain text
- Device MAC blocking and reliability history
- HMAC-signed developer webhooks and scoped API keys
Security you can hand to auditors
Questions, answered
How is one tenant kept separate from another?
Tenant isolation is enforced at the data layer — every query is scoped to the caller's tenant, so a reseller or client can never read or modify another tenant's data, regardless of the UI.
Do you support two-factor authentication?
Yes — TOTP-based two-factor authentication is available, alongside encrypted storage of credentials and secrets.
How are integration secrets protected?
Secrets are encrypted at rest and never displayed in plain text, and developer webhooks are signed with HMAC so you can verify their authenticity.
Explore more of the platform
Lock down access without slowing down
Spin up MD ConnectPro and connect your first router in minutes. Free to start, self-hosted or cloud.