Security
Security by design
These are the principles the BOSIA platform is built around. They describe our design approach and are not a statement of third-party certification.
Security principles
Identity
Users authenticate through a dedicated identity provider with single sign-on. BOSIA does not store customer passwords in its applications.
Access control
Permissions are role-based and checked on the server for every protected action. Administrative access is separated from customer access.
Tenant isolation
Customer organisations are separated, and access to data is scoped to the organisation.
Encryption principles
The platform is designed to be served over TLS; certificate management is part of each deployment. Secrets are kept out of source code, and the signing secrets BOSIA issues to products are stored encrypted.
Monitoring
Services expose health and metrics, and structured logs support investigation.
Audit
Important changes are recorded in an append-only audit trail.
Infrastructure
Services run in containers behind a hardened reverse proxy with rate limiting and security headers.
Human oversight
Higher-risk decisions keep a person in the approval loop.
Certifications and compliance