SOMA-hosted control plane
Identity, tenancy, entitlements, safe audit metadata and opaque storage pointers can be hosted. Sensitive scheme content remains in the client's approved storage account or repository.
The hosted candidate coordinates identity, tenancy, entitlement and safe audit metadata. Schedules, risk registers, model inputs and outputs remain in approved client-controlled storage.
Identity, tenancy, entitlements, safe audit metadata and opaque storage pointers can be hosted. Sensitive scheme content remains in the client's approved storage account or repository.
Clients who refuse hosted processing use the separately governed self-host deployment. That is a distinct operating model, not a weakened SaaS promise.
A private hosted candidate is available for controlled, individually-provisioned verification; public production DNS/TLS and sign-in are not yet cut over. Clients who require it can choose the separately governed self-host deployment.
| Location | Permitted | Not permitted |
|---|---|---|
| Public website | High-level enquiry details and a safe opaque request reference. | Schedules, risk registers, credentials, scheme identifiers or sensitive client detail. |
| Hosted control plane | Identity, tenant, entitlement, safe audit metadata and opaque storage pointers. | Scheme inputs, model content or generated client outputs persisted at rest. |
| Client-controlled storage | Schedules, risk registers, mappings, model inputs, reports and outputs under client-selected access and retention controls. | Cross-tenant access or access outside the agreed identity and authorisation model. |
| Repository and logs | Source code and synthetic test fixtures that pass the client-data safety gate. | Client-derived identifiers, paths, row samples, content, secrets or scheme evidence. |
No ISO 27001, Cyber Essentials, SOC 2 or equivalent certification is claimed unless an exact, current certificate is separately evidenced.
No completed external penetration test is claimed on this page. Any engagement-specific requirement must be scoped and evidenced.
Contractual controller/processor roles, international transfers, retention and terms require named legal/privacy review.
A healthy private candidate and green automated checks do not authorise public cutover, live onboarding or client reliance.
Use [email protected] with [SECURITY] in the subject. Do not include exploit material, client files or secrets in an initial public email; request a governed transfer route.
We can explain the architecture, completed machine evidence, tagged security briefing and named reviews required before release.