Authority requires audit.
This page is the audit trail.
Centertron operates inside the operational core of organisations that cannot tolerate failure. The controls below are how we earn that position — and how we keep earning it.
What is in place, today, in production.
The pillars of our operational security posture. Each measure is owned, monitored, and reviewed.
Encryption in transit and at rest
TLS 1.3 for all transit. AES-256 at rest. Keys rotated on schedule. No customer data is ever co-mingled across tenants.
RBAC, MFA, and continuous access review
Role-based access control with deny-by-default. Multi-factor authentication mandatory for all privileged roles. Quarterly access attestations.
Multi-AZ hardened cloud substrate
Enterprise-grade cloud across multiple availability zones. Immutable infrastructure. Encrypted snapshots. Documented disaster recovery procedures.
24/7 monitoring and intrusion detection
Continuous log aggregation, anomaly detection, and on-call response. Automated alerting on signatures and behavioural drift.
Sandboxed agents with a forensic audit trail
Every autonomous tool action — shell, file, code, dependency, and version-control — runs inside an isolated sandbox with a scoped filesystem and no direct host access, and is recorded to an immutable, admin-visible forensic audit trail. Anything the sandbox blocks is flagged.
Per-tenant guardrails and delivery integrity
Distributed per-tenant execution quotas and rate/concurrency limits contain noisy-neighbour impact across replicas. Integration secrets are encrypted at rest and customer-rotatable; inbound webhooks are idempotent so retries never double-charge, with optional auto-retry that heals transient failures plus a self-serve delivery-health and one-click replay trail.
Every file screened at the door, and re-screenable after
We accept only file shapes we can fully validate: the true type is read from the file’s own bytes and cross-checked against its name, so a renamed executable, archive, script or HTML page is refused outright. PDFs carrying JavaScript, auto-run actions, embedded files or encryption are rejected, and images are decoded and re-encoded — the bytes we store are bytes we generated. Files are served back no-sniff, sandboxed and non-framable. Repeated blocked uploads freeze the account and alert us within the minute, every file is recorded with a SHA-256, and the whole archive is re-screenable on demand — anything that fails is quarantined until a person releases it.
Frameworks we operate against.
Certifications and frameworks under active maintenance. Reports and attestations are available to qualified prospects under NDA.
How the controls are maintained.
Controls are only as strong as the practices that uphold them. These are the continuous activities, not one-time certifications.
Third-party penetration testing
Independent assessments conducted quarterly against the entire platform surface.
Continuous vulnerability scanning
Automated scanning of dependencies, containers, and infrastructure. Patches deployed on policy.
Secure development lifecycle
Threat modelling, code review, and automated security tests gate every release.
Documented incident response
Severity-tiered runbooks, on-call rotation, and post-incident review on every event.
Personnel security
Background checks, training, and least-privilege provisioning for all team members.
Data lifecycle controls
Retention policies, secure deletion, and exportable customer data on demand.
We will tell you when something is wrong.
Incident disclosure is operational, not optional. If an event impacts the confidentiality, integrity, or availability of your data, you will be notified — directly, with full context — within our published response window.
Have a question your auditors need answered?
Our security team responds to qualified questionnaires, due diligence requests, and architecture reviews directly.