Security controls are included across all plans.

The platform applies tenant-scoped authorization and data boundaries throughout the application. Documents stored in Amazon S3 use tenant-scoped object paths and server-side encryption. Production traffic is intended to use HTTPS/TLS. Optional tenant-specific field encryption and AWS KMS keys can be configured where required.

Controls described as configurable are not active until they are enabled and correctly configured for the deployment.