Tenant isolation
Every data access is constrained by mandatory workspace context and authorization policies.
Defence in depth
Every request is validated in workspace context, from identity to tenant isolation.
Trust center data is currently unavailable.
Every data access is constrained by mandatory workspace context and authorization policies.
Keycloak, PKCE, MFA and role-based controls protect the identity lifecycle.
Provider tokens and sensitive credentials are encrypted at rest and masked in logs.
Request validation, rate limits, audit trails and secure defaults protect critical flows.
Monitoring, backups, restore tests and access records support production operations.
Defined runbooks guide classification, communication and remediation.
Use our confidential reporting address for suspected issues or vulnerabilities: security@einposty.com.