Your data. Your tenant. Your rules.
ParleHub is built so an IT admin can say yes: sign-in through the identity provider you already run, files that stay inside your own Microsoft 365 or Google Workspace tenant, and a record of who did what that nobody — including us — can quietly edit.
Sign in the way your org already does
Enterprise SSO means one fewer password to manage and one fewer account to deprovision when someone leaves.
- check_circle Microsoft Entra ID single sign-on, live in production today
- check_circle Google Workspace single sign-on
- check_circle Auto-provisioning by verified email domain — no manual account creation
- check_circle Org admins can require SSO and lock out password login entirely
Files that never leave your tenant
Point a project at storage you already control instead of trusting another vendor with your documents.
- check_circle SharePoint (Microsoft 365) as project storage, live in production
- check_circle Google Drive (Shared Drives) as project storage
- check_circle Least-privilege access — scoped to the specific site or drive a project connects, not your whole tenant
- check_circle Prefer a fully managed option? ParleHub Cloud storage is available on every tier
Roles that match how orgs are actually run
Four roles, each inheriting the permissions of the one below — no flat, all-or-nothing admin switch.
A ledger nobody can quietly edit
Every sensitive action — sign-ins, membership changes, budget edits, SSO configuration, model and storage changes — is written to an append-only audit log.
- check_circle Append-only enforcement at the database level, not just app-code convention
- check_circle Even a compromised admin credential can't rewrite history
- check_circle Org-wide usage and spend analytics, exportable to CSV
The details you'd ask about in a security review
Denial-of-wallet protection
Rate limiting and bounded agent tool-call loops prevent runaway spend from a stuck agent.
Two-vault secret broker
Your provider keys are stored so a single compromised credential can't expose every customer's keys.
Managed-identity-first Azure auth
Minimal long-lived static secrets across SQL, Blob Storage, and Key Vault.
CSP, HSTS & secure cookies
Baseline security headers enforced on every request.