Tenant isolation at the data layer
Every product scopes data access to the requesting organisation before it reaches storage — through tenant-scoped keys, a tenant-scoped index, or an explicit tenant check on every record fetch.
Suntel360 · Security
The questions procurement asks, answered on one page you can forward. No assurance certifications are claimed anywhere on this site, and no control below names a vendor or a version — that detail goes to your reviewers directly.
0
Security controls
0
Products isolated
0
Shared engineering standard
0
Shared credentials
Tenant isolation enforced at the data layer — through tenant-scoped keys, tenant-scoped indexes, or explicit tenant checks on every record fetch. Isolation is enforced in the access path, not assumed by the interface.
Role-based access control resolved fresh on every request. An access change takes effect immediately rather than at next sign-in. ATS has no login of its own — it authenticates every request against HRMS employee records.
Every change written to a dedicated audit log rather than inferred from a row's current state. Immutable posted documents in ERP. Server-side document visibility in HRMS. No shared credentials across products.
Controls
Described by what it guarantees rather than by what it is built on. Your reviewers get the implementation detail from us in writing.
Every product scopes data access to the requesting organisation before it reaches storage — through tenant-scoped keys, a tenant-scoped index, or an explicit tenant check on every record fetch.
In ERP, HRMS and CRM, permissions resolve fresh on every request against the user's assigned role, so an access change takes effect immediately rather than at next sign-in.
Every product runs on managed cloud compute and storage, provisioned from a version-controlled definition rather than by hand. There is no server for your team to patch.
Each service is granted permission to exactly the data and operations it uses, not broad account-wide access. A compromise of one component does not become a compromise of the estate.
Changes are written to a dedicated audit log rather than inferred from a row's current state, so who did what survives later edits to the same record.
In ERP, a submitted document cannot be edited. Corrections are made by cancelling and superseding, so a financial record's history cannot be rewritten in place.
HRMS employee documents carry public, private and HR-only classifications checked on the server against the requesting user. A direct request for a document someone should not see is refused.
There is no suite-wide identity. Each product authenticates its own users, except ATS, which deliberately has no user store and defers to HRMS employee records.
Traffic to the products is encrypted, and stored data is encrypted at rest by default rather than as an option someone has to remember to switch on.
Security Domains
From tenant isolation to audit trails, every control carries its own documentation and verification path.
Every product is built with tenant isolation, role-based access, and audit logging as first-class concerns — not afterthoughts.
Infrastructure provisioned from version-controlled definitions. Managed cloud compute and storage. No manual configuration.
Access re-checked on every request. Changes written to dedicated audit logs. Encrypted in transit and at rest by default.
Procurement-ready documentation available on request. Your reviewers get implementation detail in writing, under NDA if needed.
Ask us directly
These depend on your deployment and your requirements, so publishing a generic answer would be worse than none. Bring them to the first security call and you will get specifics.
Tell us what your review requires — questionnaire, architecture session, or both — and we will send it.