Security

Security applied to every item by design

Control access using roles, groups and specific users while giving the organization one connected risk platform.

Parapet risk workspace
Parapet user access and security features

Fine-grained access

Share what is needed, protect what is sensitive

Risk information can include sensitive operational, security, audit and third-party details. Parapet secures each object or item by design rather than relying only on broad application access.

Permissions use a role-based access control model. Access can be assigned through groups or to specific users, supporting practical separation across teams and responsibilities.

  • Role-based permissions
  • Group-based access
  • Specific-user access
  • Item-level security

Enterprise identity

Connect an OIDC-compliant identity provider

The platform supports identity providers that comply with OpenID Connect. OIDC settings are configured for each client, allowing authentication to align with the organization's identity environment.

Deployment and security requirements are reviewed during discovery. Parapet is available as SaaS, and customer-hosted deployment is available with custom pricing.

  • Client-specific OIDC configuration
  • SaaS deployment
  • Customer-hosted option
  • Access model aligned to organizational roles

Questions answered

Frequently asked questions

Does Parapet support SSO?

Yes. Parapet supports any OIDC-compliant identity provider, with settings configured for each client.

Can access be limited to one risk or control?

Yes. Security is applied at the object or item level using roles, groups and specific users.

Can we host Parapet ourselves?

Yes. Customer-hosted deployment is available and uses custom pricing based on the environment and support requirements.

A clearer view of risk

See how Parapet fits your risk program

Bring one risk register or an enterprise-wide program. We will show you the platform, pricing and a practical starting point.