- Authentication and sessions
- Email and password with strong hashing, plus passkeys. Multi-factor authentication is mandatory for every staff role and enforced at the session level. Password-reset tokens are single-use, expiring and hashed at rest, with no account enumeration.
- Role-based access and tenant isolation
- Every request is authorised server-side. A client organisation can read only its own data. Cross-tenant access is tested per resource type as a standing regression suite.
- No card data
- The platform never receives, stores, logs or transmits a card number, CVV or expiry. Hosted checkout or tokenised fields only. PCI-DSS SAQ-A scope.
- Encryption
- TLS 1.2 or later in transit with HSTS; encryption at rest for data and documents.
- Private storage
- Client documents live in a private bucket with public read disabled and verified by test, served only through short-lived signed URLs, with every download recorded.
- Audit logging
- Every privileged write records actor, action, entity, before and after values, timestamp and request identifier. The log is append-only.
- Soft delete and retention
- Nothing is hard-deleted. Every record carries a retention class, and retention is enforced by a scheduled job.
- Backups
- Nightly backups with point-in-time recovery, and a restore rehearsed and documented before launch. An untested backup is not a backup.
- Security headers
- A content-security policy without unsafe-inline or unsafe-eval, HSTS with preload, frame-ancestors denied, a referrer policy and a permissions policy denying camera, microphone, geolocation and payment.
- Incident response and disclosure
- A documented procedure with a named owner, a security.txt with a disclosure contact, and a client-notification template.
- Sub-processors
- A published, versioned list of third parties that process data on the firm's behalf, with purpose and region.