Platform security

Security should be visible in the way the platform works.

Client information, evidence and assurance decisions are protected through deliberate access boundaries, secure defaults and regular technical review.

01

Controlled access

Separate client and consultant sessions, approved work-email access, single-use sign-in codes and short-lived secure sessions protect every private workspace.

02

Client isolation

Each business and framework has a durable boundary. Access checks and data queries remain scoped to the correct business, workspace and authorised recipient.

03

Protected evidence

Files are restricted by size and type, scanned for malware before acceptance and delivered only through authenticated, non-cached downloads.

04

Secure operation

Private services are not exposed to the internet. Encryption in transit, security headers, audit history, dependency review and tested backups support day-to-day operation.

Recognised guidance

Built around controls clients already recognise.

Alignment describes how the platform is engineered and operated. It does not represent independent certification of the platform or the wider business.

OWASP

Application security

Authentication, access control, input handling, secure configuration and dependency management are reviewed against current web-application guidance.

NCSC

Secure services

The service follows principles of least exposure, strong authentication, tenant separation, auditability and secure failure.

Cyber Essentials

Technical controls

Hosting controls support boundary protection, secure configuration, access control, malware protection and security update management.

ISO/IEC 27001

Relevant security controls

The platform supports access control, logging, network security, secure development, malware protection and backup practices.

Responsible assurance

Clear about the boundary.

A secure platform supports good compliance work; it does not turn a service provider into an accredited certification body. Formal ISO or Cyber Essentials certification is claimed only where a current, appropriately scoped certificate exists.

To report a security concern, email hello@hemanthvishnu.com.