Sintesi della postura di sicurezza

Questa sintesi descrive l'ambiente di controllo della piattaforma per clienti enterprise ed è fornita per security review e valutazioni procurement.

Governance and responsibility

Client data ownership

Client retains full ownership of tenant data.

Control boundaries

The platform provides reporting, classification, and workflow infrastructure; it does not perform custody or statutory accounting functions.

Change management

Structural changes are versioned and historical states are preserved.

Logical security

Authentication

OIDC and SAML 2.0 are supported through enterprise identity providers.

Authorisation

Tenant-scoped, role-based, and object-level controls are enforced within the platform.

Least privilege

Services and operators have access limited to required scope only.

Data protection

Encryption in transit

TLS protects external and internal communications.

Encryption at rest

Tenant data is encrypted using industry-standard mechanisms.

Data residency

Tenant-selected hosting region is enforced at infrastructure level.

Availability and resilience

Stateless services

The application layer is designed for horizontal scaling and replacement.

Fault isolation

Failures in non-critical services do not compromise core data access.

Authorisation resilience

Authorisation state remains consistent during identity-provider outages.

Auditability and integrity

Change traceability

Reporting and classification changes are historically traceable.

No silent mutation

The platform does not auto-adjust, rebalance, or normalise data without explicit action.

Deterministic computation

Outputs are reproducible from stored inputs.

Third-party dependencies

Identity provider

Enterprise-grade provider for SSO and federation.

Infrastructure

Cloud-based infrastructure with region-specific deployment.

Dependency review

External services are limited to necessary operational functions.

Tecnologia

Comprendi come architettura dati e infrastruttura supportano operazioni critiche con sicurezza e scala.

Tecnologia