We treat your security exceptions with the highest standard of confidentiality, isolation, and cryptographic integrity.
Multi-tenancy is enforced at the database query abstraction layer (enforce_tenant_scope). Every SQL transaction, read, and write is automatically bound to the authenticated user's verified JWT tenant identifier. Cross-tenant access is structurally impossible.
Granular permission dependencies protect all API routes. Roles include Administrator, Security Approver, Requester, and Compliance Auditor. Requester cannot approve their own exceptions (enforced Segregation of Duties).
All state mutations (login, creation, review, transition, renewal, evidence upload/deletion) produce structured, tamper-resistant audit events recording actor ID, tenant ID, client IP, and UTC timestamps.
TLS 1.3 enforced for all browser and API communications. Object storage artifacts and database volumes are encrypted using AES-256 with optional Customer-Managed KMS keys on Enterprise plans.
CC6.1, CC6.6, CC6.8 Access Control & Change Management
A.5.8 Information Security in Project Management & A.8.32
Requirement 6.4 & 12.3.2 Documented Security Exceptions
GV.RM-06 Risk Management & Continuous Authorization