Adm Cloud i-ERP · Security

Your business protected, down to the last click

Adm Cloud protects your data with enterprise-grade security: decide who gets in, what each person can see and do, and keep a record of everything. Multi-factor authentication, strong passwords, access control by day, time and IP, and an audit log that leaves nothing untracked.

Includes
Multi-factor authentication Role-based privileges Audit log IP and schedule control
2authentication factors (MFA)
6privilege levels per action
100%of actions in the audit log
24/7access and threat monitoring
The approach

Security built into the entire ERP, not an add-on

Adm Cloud security is not a separate module: it accompanies every screen and every operation. It is organized into three fronts that work together to protect your information.

Who gets in and what they can do

Users organized into groups with granular privileges. Each person sees and modifies only what their role allows — by module, by action, and even by branch.

How they authenticate

Multi-factor authentication, complex passwords with periodic renewal, and access control by day, time and IP. Only the right people get in, from where they should.

What gets recorded

An audit log records who did what, when and from where — with the values before and after every change. Nothing is lost and everything is traceable.

Capabilities

A complete arsenal of security controls

From user management to real-time threat monitoring. These are the controls that protect your Adm Cloud, all manageable from within the system itself.

Users

Manage your company's users, invite them by email and control their status. The same user can belong to several companies with different roles.

UsersMulti-company

User groups and roles

Organize people into groups (roles) and define their permissions, data scope and security behavior in a single place.

User GroupsAdministrator

Granular privileges

Grant access by module and by action: view, create, edit, delete, authorize and void. Authorize and void are independent permissions.

View · Create · EditAuthorize · Void

Menu and form access

Beyond permissions, control which menu options and which custom forms and reports each user group can see.

Menu accessForms and reports

Multi-factor authentication (MFA)

Second factor via authenticator app (TOTP) or a one-time code by email. It can be required for an entire user group.

Authenticator app (TOTP)Code by email

Strong passwords and renewal

Mandatory strong passwords, no reuse of the previous one, and periodic renewal. They are stored encrypted, never in plain text.

Minimum 10 charactersRenewal every 180 days

Access by day and schedule

Define for each employee which days of the week and within which time window they can sign in. Outside that range, access is blocked.

Allowed daysTime window

IP restriction

Limit which IP addresses or ranges each employee can connect from, with an additional layer of firewall rules at the database.

Allowed IP rangeDatabase firewall

Audit log

Every creation, change, deletion, authorization or void is recorded with user, date, screen, and the before-and-after values.

Before-and-after valuesGeolocation

Access and threat monitoring

Logs every sign-in attempt with IP, country and device. Blocks high-risk countries, detects impossible travel and checks IP reputation.

Country blockingIP reputation

Lockout after failed attempts

After repeated password attempts, the system warns and locks the account, notifying by email. Only one active session per user is allowed.

Lockout after several attemptsSingle session

Data isolation

Each company lives in its own database, isolated from the rest. Within the company, data is scoped by branch, location and employee.

Database per companyBy branch and location
Access control

Everyone sees and does exactly what they are meant to

Users, groups and privileges work in layers to give you fine-grained control without complexity. You define the permission once at the group level and it applies to everyone in that role.

From the general to the specific

Permissions are assigned per group and drill down to the detail: which modules, which actions and over which data. That way you separate duties and reduce the risk of errors and fraud.

By module

Sales, purchasing, accounting, inventory, payroll… each area is enabled separately.

By action

View, create, edit, delete, authorize and void: six independent levels.

By data scope

Limit what each role sees by branch, location and employee, even within the same company.

User group Sales
Privileges
Module View Create Edit Del. Auth. Void
Quotes
Invoicing
Accounts receivable
Accounting
Authentication and access policies

Only the right people, from where they should be

On top of permission control comes a second wall: how, when and from where users can sign in. Multiple layers you can combine to match your company's level of rigor.

Multi-factor authentication (MFA)

Add a second factor with an authenticator app (time-based TOTP code) or a one-time code sent by email. The administrator can require MFA for an entire user group; the trusted device skips the step for 7 days.

Authenticator appCode by emailTrusted device

Strong passwords and renewal

Passwords require a minimum of 10 characters with uppercase, lowercase and numbers, cannot repeat the previous one, and are renewed every 180 days. They are stored encrypted, and every change is notified to you by email with the originating IP and device.

Minimum 10 charactersNo reuse180-day renewal

Access by day and schedule

Define for each employee which days of the week and within which time window they can sign in. An attempt outside the schedule or on a non-allowed day is rejected automatically, evaluated against the company's time zone.

Days of the weekStart and end time

IP restriction

Allow access only from the IP addresses or ranges authorized for each employee — for example, the office network — with an extra layer of firewall rules at the database level.

Allowed IP rangeDatabase firewall

Attack protection

After several failed password attempts, the account is locked and a notification is sent by email. The system blocks high-risk countries, detects simultaneous sign-ins from different countries (impossible travel) and checks the reputation of every IP.

Lockout after attemptsCountry blockingIP reputation

Sessions and devices under control

Only one active session per user: if another one opens on a different device, the previous one is closed. Password recovery links are single-use and expire within minutes.

Single sessionExpiring links
Auditing and traceability

Nothing happens without leaving a trace

The audit log records every operation with the level of detail that management and formal reviews demand. If something changed, you will know who, when, from where and what was there before.

Audit log Entry #4821 EDIT
UserAna Gómez
Date21/07/2026 · 08:52
ScreenSales invoice
DocumentFAC-001042
Modified fields
Amount RD$ 12,400 RD$ 13,900
Customer Ferretería Central Distribuidora del Este
190.80.14.22 · Santo Domingo, DR · User interface

What every entry captures

Every event — creation, edit, deletion, authorization, void or status change — is documented with its full context, ready to review or export whenever you need it.

  • Who: the user responsible for the action
  • When: the exact date and time of the event
  • What: the screen, the document and the type of action
  • The before and after of every modified field
  • From where: IP, country, device and geolocation
  • The source: user interface, API or online store
How it is set up

Configure security to fit your business

In just a few steps you define who gets in, under which rules and with what oversight. All from within Adm Cloud itself.

1

Create your company's users

Invite each person by email. The same user can work in several companies, each with its own role.

2

Organize them into user groups

Define roles such as Sales, Accounting or Administrator. Mark which ones are administrators and what data scope they have.

3

Assign privileges and access

Set, by module and action, what each group can view, create, edit, delete, authorize or void, plus their menus and forms.

4

Activate the access policies

Require MFA for the groups that need it and define each employee's allowed days, schedules and IPs for signing in.

5

Supervise with the log and auditing

Review the audit log and the security report to check access, changes and potential risks at any time.

Advantages

Why companies trust their data to Adm Cloud

Control, traceability and real protection, with no need for external tools or dedicated technical staff.

Audit-ready

The audit log and the audit report give you the traceability that management and formal reviews demand.

Less fraud and fewer errors

Segregation of duties — authorize and void as separate permissions — prevents a single person from controlling the entire process.

Protection against unauthorized access

MFA, IP and schedule control, attempt-based lockout and threat monitoring shut the door on unauthorized access.

Control in your hands

You define who sees and does what, and adjust it whenever you need to, without depending on third parties or programming.

Frequently asked questions

We answer your questions

Can I limit what each user can do?

Yes. Permissions are assigned per user group and are granular: for each module you define whether the group can view, create, edit, delete, authorize or void. Authorize and void are independent permissions, and you also control which menus, forms and reports each group can access.

How does multi-factor authentication (MFA) work?

You can use an authenticator app that generates a time-based code (TOTP) or receive a one-time code by email. The administrator can require MFA for an entire user group. Once verified, the device becomes trusted and the second factor is not requested again for 7 days.

What gets recorded in the audit log?

Every creation, edit, deletion, authorization, void or status change, with the responsible user, the date and time, the screen and the document, the before-and-after values of every modified field, and the origin of the access (IP, country, device and geolocation). It also records whether the action came from the user interface, the API or the online store.

Can I restrict where and when users connect from?

Yes. For each employee you can define the days of the week and the time window in which they can sign in, as well as the allowed IP addresses or ranges. Any attempt outside those rules is rejected automatically.

What password policy does Adm Cloud enforce?

Passwords must be at least 10 characters long with uppercase, lowercase and numbers, cannot repeat the previous password, and are renewed every 180 days. They are always stored encrypted, and every change is notified to you by email with the originating IP and device.

What happens if someone tries to guess a password?

After several failed attempts the system warns and then locks the account, sending an email notification with the device details. On top of that come high-risk country blocking, detection of simultaneous sign-ins from different countries, and IP reputation checks.

Is one company's data separated from another's?

Yes. Each company resides in its own database, isolated from the rest. Within the same company, access to information is further scoped by branch, location and employee according to the user group.

Protect your business with Adm Cloud security

Access control, robust authentication and complete auditing, built into the same ERP that already runs your operation.