Security & Compliance | Abaci

Built to operate within enterprise controls.

Security, risk and governance are considered as part of every engagement. We work within the controls and assurance requirements already established across the organisation, aligning our services and technology with the environment in which they need to operate.



Identity and access

Access begins with establishing who or what is making a request, then applying the authority appropriate to that identity and the business context.

Authentication

User authentication establishes the identity behind an action before access is evaluated.

Privileged access

Privileged capabilities can be restricted to authorised roles and governed actions.

Service identities

Workflows, integrations and agents are treated as identifiable actors with their own control path.

Data protection

Data protection covers how information is transmitted, stored, accessed and separated throughout the platform and its integrations.

Encryption

Encryption is considered for data in transit and at rest according to the deployment and service configuration.

Keys and secrets

Key management and secrets handling are treated as controlled operational concerns, separate from application content.

Isolation

Tenant, organisation, entity and record boundaries support separation of data and authority.

Infrastructure and deployment

Deployment architecture determines where the platform runs, how environments are separated and which network and residency requirements apply.

Deployment choices

Cloud, private and managed deployment models can be discussed against the organisation's operating requirements.

Environment separation

Development, test and production environments should be separated according to the risk and release model.

Network and residency

Network controls and data residency considerations are addressed as part of solution architecture.

Operational security

Security depends on the practices that keep systems observable, maintained and recoverable after deployment.

Logging and monitoring

Operational activity, control decisions and relevant system events provide the basis for monitoring and investigation.

Vulnerability management

Dependencies, infrastructure and application changes require ongoing review as part of operational maintenance.

Recovery and incidents

Backup, recovery and incident-handling expectations should be agreed with the deployment and service model.

Secure development

Security is also shaped by how changes are reviewed, tested and released into the platform and its supporting services.

Change control

Changes are reviewed and progressed through an intentional release process rather than applied without traceability.

Dependencies

Third-party dependencies and package changes are part of the development and maintenance review surface.

Testing and release

Testing and release practices are used to reduce regressions and make production changes accountable.

Compliance and assurance

Assurance is tailored to the service, deployment model and requirements of each engagement, with the appropriate evidence and documentation provided as part of the customer review process.

Security review

We can discuss the relevant architecture, controls and operating responsibilities during a customer security review.

Evidence and responsibilities

The security conversation should distinguish platform controls, deployment controls and customer responsibilities.

Request information

Contact us for the security information relevant to your organisation, use case and deployment requirements.

Understand the security approach before you commit.

Request security information or speak with us about the controls, assurance requirements and operating environment that need to shape the solution.

Request security information