Security, Privacy & Continuity
This trust center summarizes the current security architecture and the evidence expected for production supplier qualification. It intentionally avoids claiming third-party certifications that have not been obtained.
Tenant isolation
Rev3.0.4 introduced a provisioning architecture designed to give each customer organization a separate operational database and organization-bound authentication context. Production deployment must validate that one tenant cannot select or access another tenant’s database.
Access & records
- Role-based permissions
- Organization-scoped authorization
- Electronic approval and audit-history features
- HTTPS required by deployment guidance
- No passwords or database credentials sent by setup email
Backup / disaster recovery
Backup tooling and operational guidance are part of the application package, but customer qualification should require documented backup schedules, off-site copies, restore tests, recovery-point objectives (RPO), recovery-time objectives (RTO), and evidence from completed tests.
RESTORE EVIDENCE REQUIRED
Independent assurance
NOT CURRENTLY CLAIMED
No SOC 2 Type II, ISO 27001, FedRAMP or CMMC certification is claimed here. A penetration-test summary and third-party assurance package should be obtained before high-assurance aerospace/defense deployment.