Security and deployment
Data residency, identity, record integrity and resilience: we spell out how it is designed and what stays with you.
Identity and access
Identity is managed with Keycloak. Role-based authorization, identity re-authentication at signing and segregation-of-duties checks apply.
- Corporate identity-provider integration
- Re-authentication for signatures
- Segregation-of-duties (SoD) rules
Record integrity
The audit trail is protected as append-only (WORM) with PostgreSQL triggers and rows are chained with SHA-256.
- Database rules that block update and delete
- Chain verification
- Raw-payload visibility
Data residency
In an on-premise install your data stays on your infrastructure. The evaluation demo environment runs on GCP with illustrative data.
- On-premise and air-gapped options
- No real data in the demo environment
- AI data flow is clarified per deployment model
Multi-site isolation
Sites run their own operations while corporate quality rules are managed centrally.
- Per-site data separation
- Corporate policy layer
- Shared audit view
Resilience
Backup, restore and disaster-recovery plans are defined together with your policies during installation.
- Backup plan per installation
- Suggested restore drill
- Operations documents
Deployment models
On-premise / air-gapped
Runs on your own infrastructure. Data does not have to leave your site network.
The customer is the data controller.
GCP demo environment
An instance with illustrative data opened for evaluation. Not for real production data.
Roles are defined separately for the demo user.