Six pillars, live in production today.
Field-level PII encryption, a client redaction library and a records-retention engine. All client documents are stored encrypted in EU-region object storage, served only through short-lived signed links.
Sixteen roles enforced server-side, per-route entitlement gates, session policy with step-up re-authentication, CSRF protection and rate limiting. Admin bridges are HMAC-signed; impersonation is gated and audited.
SHA-256 hash chains — each entry folds in the previous hash — across ten-plus registers, with a nightly chain-verification job. A full audit trail sits on every record change.
EU-hosted, multi-tenant by design. Tenant data is isolated at the application layer, with per-tenant database schemas and per-tenant data residency available on request.
Qualified e-signature (QES / AES / SES) through a Swiss-regulated provider, compliant with ZertES and eIDAS, with hardened signature webhooks.
Every model call routes through one governed gateway with per-tenant policy, confidence floors and audit-hashed logging. No autonomous approvals, payments or trades; low-confidence outputs route to human review.
Responsible disclosure: report a suspected vulnerability to security@stellon.com. We acknowledge within one business day.