Security evidence map

Controls, boundaries, and evidence without inflated claims.

This public map separates implemented controls, architectural boundaries, validation work, framework alignment, certification targets, and deployment-specific evidence. It is an evaluation aid—not a certification statement.

Authentication & sessions
Implemented

Server-side sessions, password controls, revocation, and privileged authorization are part of the current application foundation.

Role-based access
Implemented

Operational permissions and privileged actions are enforced inside protected application workflows according to assigned roles.

Customer data boundaries
Implemented / architectural

Operational identity, watchlist, case, evidence, and regulated-source data is separated from public website activity and restricted to authorized customer workflows.

Credential handling
Implemented / architectural

Secrets, API credentials, session material, database credentials, and protected integration data are excluded from public surfaces and client-side configuration.

Audit & retention
Implemented foundation

Relevant security and operational history can be retained under role-based access and configured lifecycle policy.

Backup & recovery
In validation

Deployment-specific backup, recovery, readiness, and continuity controls are validated against the selected operating model.

Public lead intake
Implemented

The website accepts business evaluation data rather than patron identity records and validates contact intake server-side.

Framework mapping
Aligned / mapped

Security controls and engineering practices are being mapped to applicable NIST, OWASP, and CIS guidance without representing that mapping as certification.

SOC 2
Certification target

SOC 2 is a future independent-assurance target and is not represented as currently awarded.

ISO/IEC 27001
Certification target

ISO/IEC 27001 is a future certification target and is not represented as currently awarded.

Legal / regulatory evidence
Deployment-specific

Privacy positions, processor disclosures, regulatory mappings, and jurisdiction-specific evidence are verified for the actual deployment before they are relied upon.

Customer review

Security evidence should answer practical questions.

Who can access protected records? Where does customer data live? How are credentials handled? What activity is auditable? What happens during degraded operation? How are backups, retention, integrations, and administrative changes controlled? IDSENTRA's trust materials are organized around those questions.

Review customer architecture →