Security Guide

Goal: Protect your data and manage access securely.


Security Architecture

LayerProtection
NetworkHTTPS everywhere, TLS 1.3
AuthenticationAzure AD B2C, SSO, MFA
AuthorizationRole-based access control
DataEncryption at rest and in transit
AuditEvery action logged

Key Security Features

1. Connection Security

  • All data connections use encrypted protocols
  • Credentials stored in Azure Key Vault
  • Connection strings never exposed in UI

2. API Security

  • JWT tokens with configurable expiry
  • Rate limiting per token
  • Scope-limited access

3. Audit Trail

  • Who did what, when
  • Immutable logs
  • Export for compliance

Governance isn't optional. Every query, every change, every API call is tracked and attributable.


Private Cloud Security

When deployed to your infrastructure:

AspectYour Control
NetworkYour VNet, your firewall rules
IdentityYour Azure AD tenant
DataNever leaves your boundary
ComplianceYour certifications
Cloud connections security

Common Security Tasks

TaskGuide
Create API keysSecrets Management →
Configure JWT expirySecrets Management →
Review audit logsUser Management →
Manage team accessPermissions →

Compliance

StandardStatus
SOC 2 Type IIIn progress
GDPRCompliant
HIPAABAA available (Enterprise)

Next Steps

If you want to...Go to...
Manage API credentialsSecrets →
Control team accessPermissions →
Understand audit systemUser Management →
On this page