Identity & access
Strong authentication/federation, scoped authorization and step-up for sensitive actions where configured.
TRUST
Layered identity, least privilege, encryption, segmented integration, logging and operational controls protect the platform within the published service boundary.
Strong authentication/federation, scoped authorization and step-up for sensitive actions where configured.
Transport protection, protected secret/key handling and controlled data access.
mTLS/OAuth, allowlisted endpoints and dependency isolation according to deployment.
Security-relevant logs, service observability, incident triage and controlled remediation.
Customer identity configuration, endpoints, user lifecycle and external systems remain shared/customer responsibilities as agreed per deployment.
Report suspected vulnerabilities through Security Reporting; operational incidents follow the contracted operations channel, with the minimum sensitive detail needed for triage.