Security and data

Controls explained as they are, without compliance slogans

ARMADA uses tenant data isolation, default-deny access, an event trail, and posted documents that preserve history. Hosting, backup, and response responsibilities are defined for each environment in the contract.

Controls that begin with system structure

Tenant isolation

A separate database for each tenant with defined hostname routing.

Default denial

An absent permission rejects the action instead of silently allowing it.

Operational context

Permissions know the relevant company, branch, and scope.

Event trail

Important events use identifiers that support traceability and prevent duplicate effects.

Protecting operational and financial truth

Posted documents do not change

Correction uses reversal or a new document so history remains auditable.

Conflicting writes are rejected

Every write checks record version, while critical operations lock their transaction.

Recoverable processing

Failures retry through a controlled path and move to review instead of silent deletion.

Data handling

Minimum necessary data

Every collected field needs a defined purpose.

Retention

Periods are defined legally and contractually by data type and purpose.

Analytics without contact data

Names, phone numbers, and email addresses are not sent to general analytics tools.

Responsibilities stated clearly in the contract

Environment

Hosting location, domains, and operating responsibilities.

Backup and recovery

A documented policy and recovery test for the specific environment.

Response

Escalation channels, roles, and an incident record.

These controls do not represent a security certification or regulatory compliance unless the approval is named and evidenced in the contract.

Security is a shared responsibility

ARMADA controls system structure and agreed operations. The customer owns user assignment, internal roles, devices, and access policies. Every external integration states its data, permissions, and monitoring responsibility in the implementation scope.

Frequently asked questions

Clear answers before you decide

How are access and data handled?

The design uses isolation, default denial, scoped permissions, and an event trail. Actual environment, backup, and retention details are presented in a technical review before contracting, without unverified certification claims.