01
Control Surface
Identity and auth
Passkeys, MFA, SSO through SAML or OIDC, and device checks for administrative actions.
Secrets and keys
KMS-backed encryption, key rotation, per-environment isolation, and no secrets in code.
Data security
AES-256 at rest, TLS in transit, row-level isolation, and field-level controls for sensitive data.
Approval gates
Co-approval for mass send, data export, permission changes, and other sensitive operations.
Evidence and logs
Action logs capture actor, scope, result, and timing, with retention configurable by the operation.
Network posture
IP allowlists, private networking or VPC peering options, and egress controls where the deployment requires them.