CC / Security
Security
We protect the portal from unauthorized access, whether from the internet or from inside our own team.
Controls we operate
- Zero-trust network segmentation between the public portal and any institutional bridge — no persistent trust between segments.
- SSO + phishing-resistant MFA for every employee; hardware keys for anyone with production access.
- Least-privilege IAM reviewed quarterly. Access is time-bound and requires approval on every request.
- 24/7 log aggregation with automated alerting for anomalous authentication, data export, and privilege escalation.
Evidence
Shared with pilot partners under NDA.
