Identity & access
External identity providers, local-account MFA, roles, policies, claims, and record-aware authorization work together.
Risk Vault layers tenant boundaries, identity controls, fine-grained authorization, encryption, and audit records around the data that informs consequential decisions.
Deployment options can provide an isolated application and data environment, including models hosted in a customer-controlled AWS account or a managed single-tenant environment, subject to the selected offering.
External identity providers, local-account MFA, roles, policies, claims, and record-aware authorization work together.
Protect data in transit and at rest, with supported key-management choices aligned to the deployment architecture.
Capture security-relevant actions, workflow history, integration events, and administrative changes for oversight.
Apply access rules to screens, counts, dashboards, reports, exports, APIs, and background delivery—not only navigation.
Use signed webhooks, protected credentials, monitored delivery, and scoped integration administration.
AI-enabled capabilities can be deployed with privacy-conscious model choices appropriate to the approved environment and configuration.
Architecture, key management, identity provider support, retention, logging, monitoring, recovery, and assurance materials should be evaluated against the deployment option and product release under consideration.
Contact us for the current security overview and technical review materials.
Contact security