Security Centre

Control every document, identity and business boundary.

Aperture Flow is designed around least-privilege access, business-unit isolation, authenticated audit history and controlled document processing on Microsoft Azure.

Practical controls

Security across the document lifecycle.

Claims are limited to product capabilities and deployment design. Formal certifications are not claimed unless independently achieved.

01

Deny-by-default permissions

API actions are explicitly mapped to roles rather than inferred from page names or browser behaviour.

02

Business-unit isolation

Document access is restricted by assigned company, division, dealership or operational unit.

03

Authenticated audit identity

History derives the acting identity from the signed-in session, not browser-supplied names.

04

Controlled document states

Approved and exported records can be locked while genuine validation work remains editable.

05

File validation

Uploads are checked against expected signatures and processing constraints before extraction.

06

Complete processing history

Capture, edits, decisions, approvals, exports and operational exceptions remain traceable.

Microsoft Azure

Azure-hosted and integration ready.

The current deployment uses Azure App Service, with supporting architecture adapted to the customer's agreed environment, scale and security requirements.

Azure App ServiceAzure Document IntelligenceEnvironment-specific deploymentControlled integration
Procurement answers

Clear answers for security teams.

Where is Aperture Flow hosted?

The current deployment is hosted using Microsoft Azure App Service. Customer architecture can be adapted to the agreed environment and requirements.

Can access be restricted by business unit?

Yes. Users can be restricted to assigned business units and only access documents belonging to authorised areas.

Are user actions audited?

The platform records material document actions, edits, decisions and exports using the authenticated user identity.

Does Aperture Flow claim ISO 27001 or SOC 2 certification?

No. Formal certification claims are not presented unless those certifications have been obtained and can be evidenced.

Start the security conversation early.

We can walk through access, document isolation, audit history and deployment architecture as part of your demonstration.

Book a tailored demo