How is the solution protected against cyberattacks and unauthorised access?
Security is implemented as a layered combination of architecture, access control, operational controls, and continuous monitoring rather than as a single technical component.
Each customer solution is deployed in an isolated customer environment in Amazon AWS (EU/Ireland), with separate application environments, database/storage resources, source-code/CI/CD repositories, and controlled access boundaries. External access is protected through managed HTTPS/TLS endpoints and AWS network/edge controls, including CloudFront and AWS WAF where applicable, together with load balancing and controlled network access.
At application level, access is controlled through authentication and authorisation, role-based access control (RBAC), and least-privilege permissions. SSO and MFA can be enabled where required. Business data and private files are not anonymously accessible; file access is controlled through authorised/signed access mechanisms, and credentials and secrets are kept in restricted secret-storage systems.
Development and production operations are separated across test, staging, and production environments. Production changes are delivered through controlled CI/CD pipelines with traceable source history, review, testing/regression, and auditable releases. The environment is continuously monitored and logged, with automated alerting, backups, and database point-in-time recovery. Normal security, framework, and compatibility updates required to keep the solution current are part of ongoing Maintenance and SLA.