Security

Security controls and measures to protect information and operate with traceability.

Data protection

  • Data residency in the European Union.
  • Encryption in transit using TLS.
  • Encryption at rest for storage and backups.
  • Logical data isolation per organization (multi-tenant architecture with per-customer separation).

Operational control

  • Role-based access control and permissions.
  • Activity logging for auditability and follow-up.
  • Periodic backups with restore testing.
  • Multi-factor authentication (MFA) available on every plan.

Secure development

  • Development aligned with OWASP best practices (Top 10 / ASVS).
  • Separate development, staging and production environments.
  • Secrets and credentials managed outside the source code.
  • Code review before every production deployment.

Subprocessors

Auditlean works with infrastructure and auxiliary service subprocessors under data processing agreements.

ISO/IEC 27001 certification applies to the infrastructure providers used by Auditlean.