Built to operate within enterprise controls.
Security, risk and governance are considered as part of every engagement. We work within the controls and assurance requirements already established across the organisation, aligning our services and technology with the environment in which they need to operate.
Identity and access
Access begins with establishing who or what is making a request, then applying the authority appropriate to that identity and the business context.
Authentication
User authentication establishes the identity behind an action before access is evaluated.
Privileged access
Privileged capabilities can be restricted to authorised roles and governed actions.
Service identities
Workflows, integrations and agents are treated as identifiable actors with their own control path.
Data protection
Data protection covers how information is transmitted, stored, accessed and separated throughout the platform and its integrations.
Encryption
Encryption is considered for data in transit and at rest according to the deployment and service configuration.
Keys and secrets
Key management and secrets handling are treated as controlled operational concerns, separate from application content.
Isolation
Tenant, organisation, entity and record boundaries support separation of data and authority.
Infrastructure and deployment
Deployment architecture determines where the platform runs, how environments are separated and which network and residency requirements apply.
Deployment choices
Cloud, private and managed deployment models can be discussed against the organisation's operating requirements.
Environment separation
Development, test and production environments should be separated according to the risk and release model.
Network and residency
Network controls and data residency considerations are addressed as part of solution architecture.
Operational security
Security depends on the practices that keep systems observable, maintained and recoverable after deployment.
Logging and monitoring
Operational activity, control decisions and relevant system events provide the basis for monitoring and investigation.
Vulnerability management
Dependencies, infrastructure and application changes require ongoing review as part of operational maintenance.
Recovery and incidents
Backup, recovery and incident-handling expectations should be agreed with the deployment and service model.
Secure development
Security is also shaped by how changes are reviewed, tested and released into the platform and its supporting services.
Change control
Changes are reviewed and progressed through an intentional release process rather than applied without traceability.
Dependencies
Third-party dependencies and package changes are part of the development and maintenance review surface.
Testing and release
Testing and release practices are used to reduce regressions and make production changes accountable.
Compliance and assurance
Assurance is tailored to the service, deployment model and requirements of each engagement, with the appropriate evidence and documentation provided as part of the customer review process.
Security review
We can discuss the relevant architecture, controls and operating responsibilities during a customer security review.
Evidence and responsibilities
The security conversation should distinguish platform controls, deployment controls and customer responsibilities.
Request information
Contact us for the security information relevant to your organisation, use case and deployment requirements.