Start a project Sign in
Security

How the platform is built and defended.

The full whitepaper is a PDF under NDA. Everything material is summarised here so your security team can start the review today.

01

Architecture

●One decision core behind a single API. Surfaces call the same endpoint; there is no second code path with weaker checks.●Tenant isolation at the data layer — catalogue, signals and decisions are partitioned per account.●Every decision writes an immutable record: inputs referenced, engines used, reason returned.
02

Encryption and keys

In transitTLS 1.3At restAES-256Key managementmanaged KMS, annual rotationSecretsshort-lived, no long-lived shared keys
03

Access control

●SSO with SAML, enforced per account; two-factor required for every console user.●Role separation in the console: admin, operator, analyst, developer — each with a fixed scope.●Staff access is just-in-time, approved, logged and reviewed monthly. No standing production access.
04

Testing and assurance

ActivityCadenceEvidence
Third-party penetration testAnnualSummary letter under NDA
Dependency and container scanningContinuousDashboard on request
Restore test from backupQuarterlyResult log
SOC 2 Type IIIn progressReadiness report available
ISO 27001Planned 2027Roadmap on request
05

Request the whitepaper

Email contact@specicon.com from your corporate domain. We return the PDF and, if you need it, our completed CAIQ or your own questionnaire within five business days.

Talk to us Back to Trust & Security