Security

Isolation, control and accountability by design.

Security requirements are established during scoping, mapped to the selected infrastructure and documented in the operating model for each engagement.

Control framework

A dedicated environment with a defined trust boundary.

Specific controls, evidence and service commitments are agreed contractually for the selected deployment. We do not imply certifications that have not been scoped to that environment.

Infrastructure isolation

Single-tenant architecture, separated customer environments and defined controls for access and data handling.

Identity and access

Role-based access, multi-factor authentication and logged administrative activity within the agreed operating boundary.

Data protection

Encryption, retention and secure erasure requirements specified around customer data and the deployment lifecycle.

Assurance domains

Controls matched to the engagement.

People and access

Named roles, least-privilege access, MFA, access review and logged administrative actions are incorporated where applicable to the selected operating model.

Infrastructure and data

Customer isolation, encryption requirements, backup and recovery scope, media handling and end-of-service erasure are defined before production use.

Operations and incidents

Monitoring, escalation paths, incident communication, change controls and service responsibilities are documented between Belcastra, the customer and relevant infrastructure providers.

Data processing and supply chain

Data processing terms, relevant subprocessors, EEA transfer safeguards and supplier responsibilities are made available during contracting for the specific service.

Compliance screening

Customer, workload, sanctions and export-control screening form part of service qualification and ongoing contractual compliance.


Report a security concern.

Please send responsible disclosures to security@belcastra.com. Do not include sensitive customer data in the initial message.