Enterprise Trust Center

Security Built into Every Layer of Architecture

We treat your security exceptions with the highest standard of confidentiality, isolation, and cryptographic integrity.

🔒

Row-Level Multi-Tenant Isolation

Multi-tenancy is enforced at the database query abstraction layer (enforce_tenant_scope). Every SQL transaction, read, and write is automatically bound to the authenticated user's verified JWT tenant identifier. Cross-tenant access is structurally impossible.

🛡️

Zero Trust Role-Based Access Control (RBAC)

Granular permission dependencies protect all API routes. Roles include Administrator, Security Approver, Requester, and Compliance Auditor. Requester cannot approve their own exceptions (enforced Segregation of Duties).

📜

Immutable Append-Only Audit Trail

All state mutations (login, creation, review, transition, renewal, evidence upload/deletion) produce structured, tamper-resistant audit events recording actor ID, tenant ID, client IP, and UTC timestamps.

🔑

Encryption In-Transit & At-Rest

TLS 1.3 enforced for all browser and API communications. Object storage artifacts and database volumes are encrypted using AES-256 with optional Customer-Managed KMS keys on Enterprise plans.

Compliance Mappings

Built to Accelerate Your Audits

SOC 2 Type II

CC6.1, CC6.6, CC6.8 Access Control & Change Management

ISO 27001:2022

A.5.8 Information Security in Project Management & A.8.32

PCI-DSS v4.0

Requirement 6.4 & 12.3.2 Documented Security Exceptions

NIST CSF 2.0

GV.RM-06 Risk Management & Continuous Authorization