Security, Infrastructure & Operations
Security, Infrastructure & Operations
Trust Center — security, infrastructure, backup, incident, and human resources controls
This section is the Trust Center of the SSM.ro platform — security, infrastructure, and operations documentation intended for auditors, IT teams, and compliance teams. Most controls apply to both deployment models; differences are marked with a badge (see Deployment Models).
SSM.ro holds ISO/IEC 27001 certification for information security management — see Certifications and Standards.
Areas covered
| Area | Content |
|---|---|
| Security Policy | General information security framework |
| Access Control & Identity | RBAC, tenant isolation, local authentication, 2FA, account lockout, SSO, access review |
| Encryption | In transit, at rest, key management |
| Application Security | SDLC, OWASP, dependencies, secrets |
| Network Security | Network controls and compensating WAF controls |
| Risk Management | Methodology and risk register |
| Vulnerabilities & Testing | Scanning, patching, penetration testing |
| Infrastructure | Heroku, AWS, change management, monitoring |
| Backup & Continuity | Backup, RTO/RPO, continuity plan |
| Incident Management | Response, notifications, history |
| Human Resources & Security | Screening, access, awareness, code of conduct |
Compliance documents
The audit documentation set (DFD, architecture diagram, risk register, role catalog, WAF compensating controls memo, operational SOP) is versioned v1.0 (2026-04-29) and available to customers upon request — see Reports Available to Customers.