A common shortcut in portal software is filtering in the UI: fetch a broad set of records, then hide the ones the user shouldn’t see. It works until it doesn’t — one missed filter, one new screen, one API response inspected in the browser, and data leaks.
Basicloud takes the other path. Sharing and ownership rules are compiled into the query itself before it runs. If a record is outside a user’s scope, it is never fetched from your system in the first place — there is nothing to hide because nothing arrived.
Every request passes three gates
- Tenant. The request resolves to exactly one tenant; configuration, sessions, and data access never cross that boundary.
- Role. The user’s role decides which objects, layouts, and modules exist for them at all.
- Row. Sharing and ownership rules are enforced inside the query — the scope is narrowed before a single record moves.

Layered, never bypassed
All of this sits on top of your source system’s own permission model, not in place of it. Basicloud can narrow what a connection is allowed to see; it can never widen it. Add two-factor authentication, encrypted tokens, httpOnly-cookie sessions, and audit trails on every sensitive action, and you get a portal you can put in front of customers without holding your breath.