Security & Trust
Security built into every layer, not bolted on
The platform is designed to support enterprise security and compliance programmes. Final regulatory suitability depends on each customer's configuration, deployment, and applicable obligations.
Security principles
- Least-privilege access by default
- Segregation of duties enforced at the workflow engine
- Tamper-evident, append-only audit evidence
- Deployment portability without weakening controls
Identity and access
SSO and MFA via the customer's identity provider, role-based and attribute-based access control, conditional access, and session revocation.
Data protection
Encryption in transit (TLS 1.2+) and at rest, field-level protection for selected personal data, tenant-scoped storage, and backup encryption with key rotation.
Network and application security
Web application firewall, private endpoints, network segmentation, deny-by-default inbound rules, input validation, and anti-automation controls.
Auditability
Every state change, decision, comment, document upload, notification, and signature event is written to an append-only audit log, independent of the business record and not editable by any user — including administrators.
Secure software development
Pinned dependencies, software bill of materials, signed build artefacts, dependency and secret scanning, and static/dynamic application security testing in the delivery pipeline.
Monitoring and incident response
Centralised security monitoring, defined runbooks and escalation paths, and a documented incident response and breach-notification process.
Backup and recovery
Automated, verified backups with a recommended recovery point objective of one hour or less and recovery time objective of four hours or less for production, tested through periodic restore drills.
Deployment-specific responsibilities
Security responsibility shifts with deployment model — vendor-owned in shared SaaS, shared or vendor-managed in dedicated cloud, and customer-owned on-premises unless a managed service is contracted. Compare deployment models.
Compliance support
The platform supports compliance programmes and provides evidence for audit and regulatory review — it is configurable to organisational and sector requirements, but does not itself guarantee regulatory approval. Each customer's legal and compliance team should confirm applicable regulations, hosting restrictions, signature assurance, retention, and audit-export requirements.
Responsible disclosure
Found a security issue? Contact us at +234 902 8762 111 or via the contact form. A dedicated security disclosure mailbox is pending business approval.