Product: Provisio EHS Safety Management Suite
Provider: Safety-Chat, LLC DBA Provisio EHS
Prepared for: IT, information security, procurement, and compliance reviewers
Related resources: White paper · Executive brief
Security posture
Provisio EHS maintains a SOC 2 Type II compliance program that is underway. A Type II examination is in progress. When complete, report materials may be shared with customers under NDA or equivalent confidentiality terms.
We do not represent SOC 2 Type I or Type II as completed or certified until a report is available and confirmed.
Design principles in place today
- Security and change-management practices designed to align with SOC 2 expectations
- Tenant isolation and least-privilege access as first-class product goals
- Company-scoped treatment of sensitive operational data
- Audit-minded logging for meaningful create, update, and delete activity in business workflows
Access control
| Control | Buyer outcome |
|---|---|
| Company / tenant scoping | Users see their company’s data, not another tenant’s |
| Role-based permissions | Owners, admins, supervisors, and specialists receive least privilege |
| Invite and identity | Predictable onboarding, with SSO options where enabled |
| Multi-company models | Consultant, client, and carrier structures without shared-password workarounds |
| Admin surfaces | Clear places to manage users, roles, and company structure |
Enterprise readiness
- SSO / enterprise identity. SAML- and OIDC-style SSO options available depending on package and configuration.
- Audit-minded logging. Sensitive changes logged with who, when, and what changed (identifiers and actions; not secrets or full PII).
- Optional HR / workforce sync. Reduce duplicate user administration where integrations are enabled.
- Multi-site and partner models. Support for multi-site operations, multilingual workforce needs, and consultant or carrier multi-company structures.
Data and operational integrity
- Timestamps on business records (created / updated patterns)
- Change history for sensitive workflows (for example, incident updates)
- Append-oriented audit trails for security-relevant events
- Separated development, staging, and production practices on the engineering side
Usability supports security: a responsive field and office experience so teams stay in the system of record instead of exporting sensitive files to personal drives.
Scope and expectations
- SDS. In-app SDS tools assist chemical-hazard workflows. Customers remain responsible for verifying manufacturer-official SDS for regulatory compliance.
- Outcomes. Claim reduction, loss-ratio improvement, and similar results depend on how each organization uses the system and are not guaranteed by the software alone.
Reviewer checklist
- SOC 2 Type II program status understood (underway; report under NDA when available)
- Tenant isolation and role-based access reviewed
- SSO / identity options scoped to your package
- Audit logging and change history expectations confirmed
- SDS assistive vs manufacturer-official responsibility acknowledged
- Security questionnaire or NDA path for report materials agreed
Next step
Request a security walkthrough or an NDA path for audit materials through your Provisio EHS representative, or via Contact on https://suite.provisioehs.com.
For the full narrative, see the white paper security section.
© Safety-Chat, LLC DBA Provisio EHS. For procurement and IT review. SOC 2 wording must remain aligned with current program status.
