Security & trust

Built to protect a regulated business

Spirit Sight holds compliance-critical records and inventory worth millions. Access is controlled, every change is accountable, and you can run it on your own servers if you need to.

Access control

The right people, the right data

Role-based access

Granular roles with module-level permissions, scoped per campus so users see only their sites.

Two-factor authentication

Optional TOTP two-factor with backup codes and lockout after repeated failed attempts.

Scoped API keys

API access uses scoped, rate-limited keys (read or read/write), separate from user logins.

Accountability

Every change, on the record

Immutable audit trail

Every create, update, and delete is logged with the user, timestamp, and IP - sensitive fields redacted.

Column-level change tracking

Compliance-critical tables record the before and after of every changed field, grouped by transaction.

Reconciliation invariants

Standing checks keep operations and the general ledger in agreement, so tampering or drift shows up.

Data & deployment

Your data, your environment

On-premise or cloud

Run hosted, or deploy the self-hosted Docker stack in your own infrastructure.

Automated backups

Scheduled database backups with daily, weekly, and monthly retention.

Export anytime

Your data exports to CSV and accounting formats whenever you want it. No lock-in. See integrations.

Encrypted secrets & rate limiting

Sensitive values are encrypted at rest, and per-user and per-IP rate limits protect the API.

FAQ

Common questions

Is Spirit Sight SOC 2 certified?
We do not claim a formal certification. We can speak to our security architecture and controls in detail during an evaluation, and we support on-premise deployment for teams with strict requirements.
Can it run on our own servers?
Yes. Spirit Sight ships a self-hosted Docker stack with automated backups, so it can run in your own environment instead of the cloud.
How is access controlled across campuses?
Role-based permissions with per-campus restrictions scope each user to the data they should see. Admins can review every role and the full audit trail.

See your distillery in Spirit Sight

Book a walkthrough with our team. We’ll show your operation - barrels, TTB, and the books - in one place.

Schedule a Demo