18 regulated-industry standards mapped to specific platform capabilities. SOC 2, HIPAA, GDPR, 21 CFR Part 11, FISMA / NIST 800-53, ALCOA+ and more. Your security team doesn't start from zero.
Deployment
Self-hosted only. Air-gapped supported. Zero outbound calls. No SaaS sub-processors.
Encryption at rest
AES-256-GCM, bcrypt-12 passwords, SHA-256 API keys
RBAC
4 roles (admin / engineer / analyst / viewer) + custom per-permission grants
SSO
SAML 2.0 + OIDC: Okta, Azure AD, Google Workspace, Auth0
Provisioning
SCIM 2.0 (RFC 7644), Okta and Azure AD compatible
MFA
TOTP (RFC 6238), encrypted secret storage
Concurrent sessions
Per-user cap with oldest-session eviction. Active session list + targeted revoke.
Tamper-evident audit log
HMAC-chained append-only audit. Append-only DB trigger. Per-org advisory lock. Walkable proof for regulators.
21 CFR Part 11 e-signatures
Re-authentication + reason + HMAC or Ed25519 signature, chained into the audit log. Bulk-sign behind a separate authority gate.
ALCOA+ data integrity
Attributable, Legible, Contemporaneous, Original, Accurate plus Complete, Consistent, Enduring, Available. All nine attributes enforced.
SIEM export
JSON/CSV to Splunk, Datadog, ELK, Sumo Logic. Webhook subscriptions for live event streaming.
GDPR
Atomic erasure in one transaction: delete + anonymise + chained audit row. Article 15 subject-access endpoint included.
HIPAA
BAA-ready posture. ePHI access logged, encrypted at rest, controlled by RBAC + permissions. Audit trail covers required disclosures.
FISMA / NIST 800-53
Control families mapped (AC, AU, IA, SC, SI). Audit-ready evidence. FedRAMP-compatible deployment posture.
SOC 2
40 controls mapped, 15 fully in place, audit-ready evidence
Rate limiting
Auth: 20/15min. Management: 300/min. Runtime: configurable per key
SSRF protection
Blocks private IPs, loopback, link-local, cloud metadata endpoints. Enforced on connectors and webhook deliveries.