Built for controlled access and auditability

Authentication

OIDC (Keycloak) integration for single sign‑on and strong identity management.

Authorization

Role‑based access control (RBAC) for datasets, projects, and exports. Principle of least privilege by default.

Audit & provenance

Action logging and export versioning to support reviews, reproducibility, and regulatory processes.

Deployment flexibility

On‑prem or cloud deployment models aligned with your data residency and IT requirements.

Data handling

  • API‑first backend (GraphQL/REST) with scoped tokens and rate limiting.
  • Strict typing, validation and controlled vocabularies to prevent malformed entries.
  • Configurable export presets to minimize data leakage and enforce standards.

Need a security brief?

We can share a one‑pager covering authN/Z, logs, and deployment.