This document summarizes the security practices and controls GovSynth applies to the platform. It supplements the Terms of Service, Privacy Policy, and Data Processing Addendum.
Identity & Access
- SSO via Customer Provided Microsoft Entra ID
- RBAC enforced at tenant level
- Privileged roles restricted and logged
Data Protection
- Encryption in transit and at rest
- Key management via Azure platform and Key Vault
Logging & Monitoring
- Centralized logging via Application Insights
- Audit logging for all mutating actions
- Structured telemetry for system behavior
Secure Development
- SAST via CodeQL on all PRs
- Dependency scanning via Dependabot
- High-severity issues resolved before release
Change Management
- All changes require PR, review, and approval
- Infrastructure defined via IaC
Vulnerability Management
- Continuous scanning and patching
- Critical issues remediated prior to deployment
Incident Response
- Detection via logging and monitoring tools
- Response processes defined in separate policy
Operational Security
- Platform updates managed via Azure
- Secrets stored and managed via Key Vault
Audit & Assurance
- Security documentation available upon request
- Customer audits subject to reasonable limits