Enterprise Security

    Security at Damascus27

    Our platform is built with a security-first architecture, aligning with SOC 2 Trust Service Criteria and meeting the stringent requirements of ISO 17025 accredited laboratories across Southern Africa.

    Controls are self-attested against AICPA Trust Service Criteria (SOC 2 Type I). Independent audit planned.

    How We Protect Your Data

    Every layer of our platform is designed with defence-in-depth principles to safeguard your laboratory's critical information

    Infrastructure Overview

    Our platform runs on enterprise-grade cloud infrastructure with managed relational databases. All traffic is routed through a web application firewall with a South Africa geo-restriction policy by default, plus allow-list overrides for authorised regions. Geo-restriction is a network access control governing who may reach the platform - it is not a statement of where data is stored; hosting regions and cross-border safeguards are set out in our Privacy Policy.

    • Enterprise-grade cloud hosting
    • Managed relational databases
    • Web application firewall
    • Geo-restricted access control

    Data Isolation

    Every table in our database is protected by strict tenant-level data isolation policies, achieving complete coverage across all tables. Each tenant's data is strictly scoped to their organisation, with cross-tenant access logging and automated anomaly detection.

    • Complete data isolation across all tables
    • Tenant-scoped data access
    • Cross-tenant access logging
    • Automated anomaly detection

    Defence in Depth

    Three independent enforcement layers protect every read and write - database-level tenant isolation, application-layer tenant scoping, and component-level permission gates - so a misconfiguration at any single layer never exposes data.

    • Database-level isolation
    • Application-layer scoping
    • Component-level permission gates
    • Fail-closed by design

    Authentication & Access Control

    Multi-level role-based access control with 100+ granular permission keys, preset and custom roles, and per-user module access overrides so an individual can be confined to a subset of modules even when their organisation has broader entitlements.

    • 100+ granular permission keys
    • Preset and custom roles
    • Per-user module overrides
    • Tenant-specific role definitions

    Session Integrity

    Live sessions are bound to a device signature with mismatch detection that can terminate compromised sessions remotely. Configurable idle timeouts (30 minutes to 4 hours) and a continuous session heartbeat keep authenticated state trustworthy.

    • Device-bound sessions
    • Remote session termination
    • Configurable idle timeout
    • Continuous session heartbeat

    Encryption

    All data is encrypted in transit and at rest using industry-standard encryption protocols. User credentials are hashed using proven algorithms. No plaintext sensitive data is stored anywhere in the system.

    • Industry-standard encryption in transit
    • Industry-standard encryption at rest
    • Hashed credentials
    • No plaintext secrets

    Audit Trails

    Every significant action is recorded in tamper-evident audit trails secured by a cryptographic hash chain with continuous integrity verification - built for SANAS audit defence and full regulatory traceability.

    • Hash-chained audit trail
    • Continuous integrity verification
    • Complete traceability
    • SANAS audit ready

    Browser & Application Security

    Browser security headers, Cloudflare Turnstile bot protection on login and the Client Portal, and anti-enumeration measures across all public-facing endpoints to prevent automated attacks and data harvesting.

    • Browser security headers
    • Cloudflare Turnstile bot protection
    • Anti-enumeration measures
    • Rate limiting

    Compliance Posture

    Our platform supports and aligns with key industry standards and regulations

    ISO 17025

    Laboratory testing and calibration competence standard

    SANAS

    South African National Accreditation System compliance support

    POPIA

    Protection of Personal Information Act compliance

    GDPR

    General Data Protection Regulation alignment

    SOC 2 Alignment

    Damascus27 has completed a SOC 2 Type I self-attestation, mapping our security controls against the AICPA Trust Service Criteria. This covers Security, Availability, Processing Integrity, Confidentiality, and Privacy.

    Our self-attestation demonstrates our commitment to maintaining robust controls across all five trust service categories. We are transparent that this is a self-assessment - an independent third-party audit is planned as our platform scales.

    Transparency note: Our SOC 2 Type I attestation is self-assessed against AICPA Trust Service Criteria and has not yet been independently audited by a third-party CPA firm. We believe in transparency and will update this page as our compliance journey progresses.

    Have Security Questions?

    Our team is ready to discuss our security architecture, compliance posture, and how we protect your laboratory data.