Updated 2026-08-30

Security and trust

How Nereite PLM isolates tenants, controls access, and supports IATF 16949 document control and PPAP packages — without claiming registrar certification.

Tenant isolation

Each organization is its own tenant. Items, BOMs, changes, documents, files, workflows, and the audit log are scoped to that tenant. Another customer cannot open your records by guessing an id.

Roles and separation of duties

Access inside the tenant is role-based (for example tenant admin, development manager, BOM engineer, design engineer, quality engineer, master data specialist, viewer). Change approval is any-one eligible approver. The requestor cannot approve their own request.

External shares without supplier logins

Suppliers never get a Nereite account. You pick released documents, click Notify, and we send a link in one email and a one-time code in another. Preview is the latest released original with a visible watermark. Download is not offered on that path. Internal preview for signed-in users is unstamped so the source file stays clean.

Audit trail

Significant actions write an audit event (who, what, when). External share sessions are logged so you can see that a released drawing was opened. That trail is the evidence quality and purchasing teams ask for in a first demo.

IATF 16949 and PPAP

Nereite is not an IATF-certified certification body and does not issue PPAP approval. Automotive and industrial suppliers still need document control, revision, and a traceable packet. Nereite is built so a tenant can:

  • Keep an item master and indented BOM with keep-old part numbers searchable.
  • Run ECR/ECO with a recorded workflow instead of inbox archaeology.
  • Release a drawing revision and share only that released PDF, watermarked, via OTP.
  • Point auditors at an audit log and share access log rather than a shared mailbox.

Use those controls inside your own IATF 16949 and AIAG PPAP process. We do not replace your registrar, customer-specific requirements, or plant quality procedures.

Infrastructure

The application runs on a managed cloud database with tenant-scoped rows, object storage for files, and TLS in transit. Credentials are not stored in the browser beyond the session token your client keeps for API calls.

Sign in

Back to home