Security & compliance

Enterprise-grade security,
from day one.

ENTMAZ is built secure by design — not bolted on. Every tenant is isolated, every action is audited, and every integration is managed.


Security principles

Six non-negotiables.

Secure by design

Least privilege, deny-by-default, explicit allowlists at every boundary. Every endpoint authenticated and authorised. No anonymous paths unless explicitly specified.

Strict tenant isolation

Every customer runs in an isolated container with a separate database schema. Cross-tenant data access is architecturally impossible — not just policy-restricted.

Encryption everywhere

TLS for every request in transit. Data encrypted at rest using modern ciphers. Tenant credentials stored in managed secrets vault — never in configuration.

Rate limiting & abuse prevention

Per-user, per-endpoint, per-tenant rate limiting enforced at the gateway. Brute force protection, circuit breakers, and backpressure mechanisms.

Structured audit logging

Every sensitive action logged: who, what, when, from where, what changed. Finance-grade audit trail built into every operation. No PII in logs.

Change control & rollback

Every business model change is versioned, validated, and migration-planned before production activation. Full rollback to any previous version always available.

Identity & access

Access compiled from your business model

Roles and permissions aren't configured separately — they're compiled from your business model. The same source of truth that generates your workflows generates your access control.

Named accounts only — no shared logins
Role-based access compiled from your business model
Multi-factor authentication support
Session management with configurable expiry
Audit log for all authentication events
SSO via external identity providers

Integration security

Managed connectors. No customer-written code.

All integrations run through ENTMAZ's managed connector layer. Customers enable and configure integrations — they never write integration code or handle API credentials directly.

Credentials stored in managed secrets vault
Connector schemas define exact input/output contracts
Rate limiting and circuit breaking at gateway
Audit log for every connector call
Retry policies defined per connector type
No cross-tenant data leakage through integrations

Data protection

Your data is yours.

Data minimisation

Only data required for your compiled business model is collected and stored. No unnecessary retention.

Export & deletion

Full data export on request. Account deletion removes all tenant data. Retention policies enforced at platform level.

No cross-tenant access

Your data is inaccessible to other tenants by architecture. Separate schema, separate container, separate credentials.

Security questions before launch?

Register interest and we'll respond directly.

No spam. Early access only. Unsubscribe anytime.

Chat with us