Defence in depth

SaaS security is part of the design

Every request is validated in workspace context, from identity to tenant isolation.

Trust center data is currently unavailable.

Tenant isolation

Every data access is constrained by mandatory workspace context and authorization policies.

Identity and access

Keycloak, PKCE, MFA and role-based controls protect the identity lifecycle.

Secret management

Provider tokens and sensitive credentials are encrypted at rest and masked in logs.

Application security

Request validation, rate limits, audit trails and secure defaults protect critical flows.

Secure operations

Monitoring, backups, restore tests and access records support production operations.

Incident response

Defined runbooks guide classification, communication and remediation.

Report a security issue

Use our confidential reporting address for suspected issues or vulnerabilities: security@einposty.com.