Skip to main content
suntel360

Suntel360 · Security

Built for a security review

The questions procurement asks, answered on one page you can forward. No assurance certifications are claimed anywhere on this site, and no control below names a vendor or a version — that detail goes to your reviewers directly.

  • Isolation enforced where data is read and written
  • Access re-checked on every request, not cached into a token
  • Written for procurement, not for a search engine

0

Security controls

0

Products isolated

0

Shared engineering standard

0

Shared credentials

Isolate

Tenant isolation enforced at the data layer — through tenant-scoped keys, tenant-scoped indexes, or explicit tenant checks on every record fetch. Isolation is enforced in the access path, not assumed by the interface.

Verify

Role-based access control resolved fresh on every request. An access change takes effect immediately rather than at next sign-in. ATS has no login of its own — it authenticates every request against HRMS employee records.

Audit

Every change written to a dedicated audit log rather than inferred from a row's current state. Immutable posted documents in ERP. Server-side document visibility in HRMS. No shared credentials across products.

Controls

What is enforced, and where

Described by what it guarantees rather than by what it is built on. Your reviewers get the implementation detail from us in writing.

Tenant isolation at the data layer

Every product scopes data access to the requesting organisation before it reaches storage — through tenant-scoped keys, a tenant-scoped index, or an explicit tenant check on every record fetch.

Role-based access control

In ERP, HRMS and CRM, permissions resolve fresh on every request against the user's assigned role, so an access change takes effect immediately rather than at next sign-in.

Fully managed infrastructure

Every product runs on managed cloud compute and storage, provisioned from a version-controlled definition rather than by hand. There is no server for your team to patch.

Least-privilege service access

Each service is granted permission to exactly the data and operations it uses, not broad account-wide access. A compromise of one component does not become a compromise of the estate.

Audit trails kept apart from the record

Changes are written to a dedicated audit log rather than inferred from a row's current state, so who did what survives later edits to the same record.

Immutable posted documents

In ERP, a submitted document cannot be edited. Corrections are made by cancelling and superseding, so a financial record's history cannot be rewritten in place.

Server-side document visibility

HRMS employee documents carry public, private and HR-only classifications checked on the server against the requesting user. A direct request for a document someone should not see is refused.

No shared credential across products

There is no suite-wide identity. Each product authenticates its own users, except ATS, which deliberately has no user store and defers to HRMS employee records.

Encrypted in transit and at rest

Traffic to the products is encrypted, and stored data is encrypted at rest by default rather than as an option someone has to remember to switch on.

Security Domains

Document and control types across the estate

From tenant isolation to audit trails, every control carries its own documentation and verification path.

TENANTRBACAUDITENCRYPTINFRADOCSTENANTRBACAUDITENCRYPTINFRADOCS
1

Design

Every product is built with tenant isolation, role-based access, and audit logging as first-class concerns — not afterthoughts.

2

Deploy

Infrastructure provisioned from version-controlled definitions. Managed cloud compute and storage. No manual configuration.

3

Operate

Access re-checked on every request. Changes written to dedicated audit logs. Encrypted in transit and at rest by default.

4

Review

Procurement-ready documentation available on request. Your reviewers get implementation detail in writing, under NDA if needed.

Ask us directly

What this page deliberately does not answer

These depend on your deployment and your requirements, so publishing a generic answer would be worse than none. Bring them to the first security call and you will get specifics.

  • Data residency and the region your organisation runs in
  • Backup, retention and restore procedures
  • Penetration testing history and remediation practice
  • Incident response and notification commitments
  • Sub-processor list and vendor due diligence
  • Our infrastructure topology, in detail, under NDA
  • Your own security questionnaire, completed by our team
WORKFLOW EVALUATION SESSION

Need our security documentation?

Tell us what your review requires — questionnaire, architecture session, or both — and we will send it.