Federated by design
ERMAIGE is designed to connect governed metadata, measures and decision evidence while allowing sensitive data to remain in approved customer systems. Deployment architecture, data flows and responsibilities are defined with each customer and governed by contract.
Target security architecture
- Planned identity controls include single sign-on, role-based access, least privilege, segregation of duties and explicit human accountability.
- Target deployment patterns include customer isolation, private connectivity and controlled access to approved systems.
- Encryption in transit and at rest, with deployment-appropriate key management, is a target requirement.
- Secure development, dependency and vulnerability scanning, change control, logging and retention are planned requirements.
- Privacy impact assessment, threat modelling, incident response and coordinated vulnerability reporting are planned operating disciplines.
Data and privacy
ERMAIGE applies data minimization, purpose limitation, retention and safeguards appropriate to the sensitivity of information. Customer data handling, location, subprocessors, deletion and access requirements are documented for each deployment.
Assurance and compliance status
ERMAIGE does not claim a security certification, audit opinion or regulatory approval unless it is expressly identified in current, authorized materials. Prospective customers may request available security documentation and discuss control requirements during diligence. Future assurance milestones will be published only after they are achieved and verified.
Report a concern
For a suspected vulnerability, follow the ERMAIGE Vulnerability Disclosure Policy. For other security or privacy questions, email info@ermaige.com with an appropriate subject line.