GRC SaaS

Security & Trust

Security built into every layer, not bolted on

The platform is designed to support enterprise security and compliance programmes. Final regulatory suitability depends on each customer's configuration, deployment, and applicable obligations.

Security principles

  • Least-privilege access by default
  • Segregation of duties enforced at the workflow engine
  • Tamper-evident, append-only audit evidence
  • Deployment portability without weakening controls

Identity and access

SSO and MFA via the customer's identity provider, role-based and attribute-based access control, conditional access, and session revocation.

Data protection

Encryption in transit (TLS 1.2+) and at rest, field-level protection for selected personal data, tenant-scoped storage, and backup encryption with key rotation.

Network and application security

Web application firewall, private endpoints, network segmentation, deny-by-default inbound rules, input validation, and anti-automation controls.

Auditability

Every state change, decision, comment, document upload, notification, and signature event is written to an append-only audit log, independent of the business record and not editable by any user — including administrators.

Secure software development

Pinned dependencies, software bill of materials, signed build artefacts, dependency and secret scanning, and static/dynamic application security testing in the delivery pipeline.

Monitoring and incident response

Centralised security monitoring, defined runbooks and escalation paths, and a documented incident response and breach-notification process.

Backup and recovery

Automated, verified backups with a recommended recovery point objective of one hour or less and recovery time objective of four hours or less for production, tested through periodic restore drills.

Deployment-specific responsibilities

Security responsibility shifts with deployment model — vendor-owned in shared SaaS, shared or vendor-managed in dedicated cloud, and customer-owned on-premises unless a managed service is contracted. Compare deployment models.

Compliance support

The platform supports compliance programmes and provides evidence for audit and regulatory review — it is configurable to organisational and sector requirements, but does not itself guarantee regulatory approval. Each customer's legal and compliance team should confirm applicable regulations, hosting restrictions, signature assurance, retention, and audit-export requirements.

Responsible disclosure

Found a security issue? Contact us at +234 902 8762 111 or via the contact form. A dedicated security disclosure mailbox is pending business approval.

Discuss your security and compliance requirements.