Data encrypted at rest in EU object storage; access through short-lived signed links only.
Strategic portfolio decisions are written to an immutable, tamper-evident audit chain.
Isolation at the application layer, with per-tenant database schemas available on request.
How those controls are enforced underneath — in the platform layer, where configuration cannot switch them off.
SHA-256 hash chains — each entry folds in the previous hash — across ten-plus registers, with a nightly chain-verification job.
A platform approvals engine with delegation and escalation; the payment cycle runs a maker-checker state machine; compliance runs a CCO approval inbox.
Field-level PII encryption, a client redaction library, redaction-aware AI embeddings, a records-retention engine and per-tenant data residency.
Sixteen roles enforced server-side, per-route entitlement gates, session policy with step-up re-authentication, CSRF and rate limiting, HMAC-signed admin bridges.
Each capability is backed by a working surface in the platform today — carried here with an honest status.
Each jurisdiction runs per tenant, with a regulator-correspondence log, a versioned policy registry and document retention. Controls verified against the production codebase, August 2026.