Security & Data Protection
Versioned security controls, encryption and role-based access support a reviewable protection scope.
256-Bit Encryption
Transport and storage encryption, key management and access controls are documented and reviewed per deployment.
Row-Level Security
Tenant-specific database policies are designed for data separation and are checked through RLS and release tests.
Complete Audit Trails
Every action is logged with timestamp, user, and SHA-256 hash. Corrections follow controlled audit-trail workflows.
EU Hosting
Current hosting regions, subprocessors and any required transfer mechanisms are documented in the applicable data-governance scope.
Multi-Factor Authentication
2FA, session management, automatic lockouts for suspicious activity, and IP-based rate limiting.
Security & Privacy Review
Technical and organisational controls support review. GDPR compliance, ISO 27001 alignment and external testing apply only where documented and evidenced for the relevant scope.

