ssm.ro Docs
Security, Infrastructure & Operations

Security, Infrastructure & Operations

Trust Center — security, infrastructure, backup, incident, and human resources controls

This section is the Trust Center of the SSM.ro platform — security, infrastructure, and operations documentation intended for auditors, IT teams, and compliance teams. Most controls apply to both deployment models; differences are marked with a badge (see Deployment Models).

SSM.ro holds ISO/IEC 27001 certification for information security management — see Certifications and Standards.

Areas covered

AreaContent
Security PolicyGeneral information security framework
Access Control & IdentityRBAC, tenant isolation, local authentication, 2FA, account lockout, SSO, access review
EncryptionIn transit, at rest, key management
Application SecuritySDLC, OWASP, dependencies, secrets
Network SecurityNetwork controls and compensating WAF controls
Risk ManagementMethodology and risk register
Vulnerabilities & TestingScanning, patching, penetration testing
InfrastructureHeroku, AWS, change management, monitoring
Backup & ContinuityBackup, RTO/RPO, continuity plan
Incident ManagementResponse, notifications, history
Human Resources & SecurityScreening, access, awareness, code of conduct

Compliance documents

The audit documentation set (DFD, architecture diagram, risk register, role catalog, WAF compensating controls memo, operational SOP) is versioned v1.0 (2026-04-29) and available to customers upon request — see Reports Available to Customers.