TRUST-04 · Security Center

Security treated as a product property

Every casaios module ships with a named owner, a threat model and a documented control set. The summaries below reflect the controls currently in place; the Security Overview document goes into detail.

Control areas

Tenant isolation

Multi-tenant aware by design. Tenant context is bound to every request and enforced server-side at the data layer.

Access management

SSO and MFA for internal systems, least-privilege roles and periodic access reviews with documented approvals.

Encryption

Modern TLS in transit and encryption at rest, with documented key management responsibilities.

Monitoring & detection

Centralised logging with alerting on anomalous authentication, configuration change and bulk export activity.

Resilience

Automated backups, tested restores and documented recovery point and recovery time objectives.

People & process

Background-checked staff, onboarding security training, secure development practices and peer-reviewed changes.

Shared responsibility

casaios

Platform security, infrastructure hardening, monitoring, patching, subprocessor management and incident response.

Platform providers

Physical data centre security, hypervisor and managed service integrity for the infrastructure casaios builds on.

Customer

User lifecycle and role assignment inside your tenant, credential hygiene, and the content you choose to upload.