Security & data handling

Control plane here. Sensitive client content there.

The hosted candidate coordinates identity, tenancy, entitlement and safe audit metadata. Schedules, risk registers, model inputs and outputs remain in approved client-controlled storage.

01 · Deployment boundary

Two governed patterns, selected before any client data.

Hosted

SOMA-hosted control plane

Identity, tenancy, entitlements, safe audit metadata and opaque storage pointers can be hosted. Sensitive scheme content remains in the client's approved storage account or repository.

Separate deployment

Self-host

Clients who refuse hosted processing use the separately governed self-host deployment. That is a distinct operating model, not a weakened SaaS promise.

Current availability.

A private hosted candidate is available for controlled, individually-provisioned verification; public production DNS/TLS and sign-in are not yet cut over. Clients who require it can choose the separately governed self-host deployment.

02 · Data classes

What may exist on each side of the boundary.

LocationPermittedNot permitted
Public websiteHigh-level enquiry details and a safe opaque request reference.Schedules, risk registers, credentials, scheme identifiers or sensitive client detail.
Hosted control planeIdentity, tenant, entitlement, safe audit metadata and opaque storage pointers.Scheme inputs, model content or generated client outputs persisted at rest.
Client-controlled storageSchedules, risk registers, mappings, model inputs, reports and outputs under client-selected access and retention controls.Cross-tenant access or access outside the agreed identity and authorisation model.
Repository and logsSource code and synthetic test fixtures that pass the client-data safety gate.Client-derived identifiers, paths, row samples, content, secrets or scheme evidence.
03 · Evidence position

Machine evidence is strong; named review remains open.

  • Tenant isolation — automated negative coverage spans storage, cache, background work and output paths.
  • Provider recovery — controlled recovery evidence exists for PostgreSQL, Azure Blob, Amazon S3 and SharePoint against the private candidate.
  • Container assurance — build, smoke, SBOM and high/critical vulnerability gates passed for the exact private candidate.
  • Client-data safety — a fail-closed changed-file gate exists; repository-history incident exit actions and independent review remain controlling.
  • Human gate — a named security/data-residency reviewer must approve the exact release candidate before any final GO.
04 · Claims we do not make

No certification or testing theatre.

Formal certifications

No ISO 27001, Cyber Essentials, SOC 2 or equivalent certification is claimed unless an exact, current certificate is separately evidenced.

Penetration testing

No completed external penetration test is claimed on this page. Any engagement-specific requirement must be scoped and evidenced.

DPA and privacy

Contractual controller/processor roles, international transfers, retention and terms require named legal/privacy review.

Public production

A healthy private candidate and green automated checks do not authorise public cutover, live onboarding or client reliance.

Report a security concern

Email the operating team.

Use [email protected] with [SECURITY] in the subject. Do not include exploit material, client files or secrets in an initial public email; request a governed transfer route.

For procurement

Review the current boundary and its evidence.

We can explain the architecture, completed machine evidence, tagged security briefing and named reviews required before release.