Security
Security is part of the architecture, not an afterthought.
Audit and risk data is sensitive. Here's specifically how it's protected today.
Encrypted transport
Application traffic is served over HTTPS/TLS.
OIDC authentication
Sign-in is handled through an OpenID Connect (OIDC) identity provider rather than a custom-built login system.
Role-based access control
Access to features and data is governed by assigned roles.
Granular permissions
Permissions can be scoped beyond role defaults for finer-grained control.
Tenant isolation
The platform is built as a multi-tenant system with data isolation between tenants.
Session administration
Administrators can view and manage active sessions for their organization.
Audit logging
Administrative and audit activity within the platform is logged.
Secure session handling
Authentication sessions use secure, HTTP-only cookie handling.
Dedicated Deployment & Enhanced Security
Organizations with specific requirements can request dedicated server infrastructure and enhanced security and isolation arrangements as part of an Enterprise or tailored engagement. Deployment architecture can be evaluated according to organizational requirements, including dedicated application and database environments and private network configurations where appropriate. Contact us for availability, configuration and pricing.
These are options discussed as part of a commercial engagement, not automated self-service features, and are not automatically included in a package.
Security and compliance transparency
We believe customers should be able to understand the controls behind the platform clearly. Our security approach is based on the controls and technologies currently implemented across authentication, authorization, tenant isolation, secure communications, audit logging and infrastructure protection.
Formal third-party certifications and independent assessments may be pursued as the platform and the organization mature. Where customers have specific security, compliance or procurement requirements, our team can discuss the controls currently available and the documentation we can provide.
Questions about our security architecture?
Our team can walk your security or compliance reviewers through the details.
Prefer a live walkthrough? Book a demo