Security overview
Built for regulated environments
Guardexia uses security-first defaults: least privilege, strong tenant boundaries,
immutable audit evidence, and operational controls designed to reduce risk and simplify assurance.
At a glance
- Tenant isolation via tenancy guards and scoped queries.
- Audit integrity with immutable audit events (tamper-resistant).
- Upload controls (limits + validation) for ingestion workflows.
- Security headers + HTTPS enforced (HSTS, nosniff, referrer policy, COOP).
- Governance controls with pre-attestation risk gating and recorded acknowledgement context.
- Operational monitoring with Sentry for errors and exceptions.
Platform hardening
- Host and origin controls to reject unexpected traffic.
- No-cache for public pages to avoid stale security / marketing content.
- Secure cookie posture (HTTPS-first, same-site policy where applicable).
- HSTS enforced in production so browsers prefer HTTPS for guardexia.com.
- Transport security with modern TLS for data in transit.
Access control
- Role-based access for admin/ops workflows.
- Invitation flows for controlled user onboarding.
- Tenant scoping prevents cross-company data access.
Audit integrity
- Immutable audit events (update/delete blocked for key records).
- Evidence trails for attestations, approvals and operational actions.
- Exports support audit and assurance workflows.
Monitoring & response
- Sentry captures errors for operational visibility.
- Health checks support availability monitoring.
- Least privilege approach to operational access.
Security reviews & questionnaires
We can support vendor security reviews, onboarding questionnaires and evidence requests.