Tenant isolation
Multi-tenant aware by design. Tenant context is bound to every request and enforced server-side at the data layer.
TRUST-04 · Security Center
Every casaios module ships with a named owner, a threat model and a documented control set. The summaries below reflect the controls currently in place; the Security Overview document goes into detail.
Multi-tenant aware by design. Tenant context is bound to every request and enforced server-side at the data layer.
SSO and MFA for internal systems, least-privilege roles and periodic access reviews with documented approvals.
Modern TLS in transit and encryption at rest, with documented key management responsibilities.
Centralised logging with alerting on anomalous authentication, configuration change and bulk export activity.
Automated backups, tested restores and documented recovery point and recovery time objectives.
Background-checked staff, onboarding security training, secure development practices and peer-reviewed changes.
How casaios protects customer data: architecture, access control, encryption, monitoring and resilience.
Article 32 style control description covering confidentiality, integrity, availability and resilience.
The governing policy for information security roles, responsibilities and control objectives.
Detection, triage, containment, customer notification and post-incident review.
Recovery objectives, failover approach and continuity testing schedule.
How to report a suspected vulnerability to casaios and what to expect in response.
Platform security, infrastructure hardening, monitoring, patching, subprocessor management and incident response.
Physical data centre security, hypervisor and managed service integrity for the infrastructure casaios builds on.
User lifecycle and role assignment inside your tenant, credential hygiene, and the content you choose to upload.