Security / Governance / Trust

Security, access and operational evidence.

Connect business information, operational requirements and reviewable records—so your team can understand what happened and what needs attention.

Security depends on both application controls and the way an organisation configures, operates and reviews them. Start with clear responsibilities and evidence people can inspect. Explore configured operational approvals and quality records and evidence.

Australian foundation. International outlook.

01 / Controls in context

A boundary with a purpose.

Explore how access, actions and evidence connect in the current platform foundation.

The role sets the boundary.

Organisation membership and assigned permissions govern protected actions. Document routes check access on the server, with records scoped to the organisation.

  • Organisation context
  • Role permissions
  • Server-side checks
Control details

Protected document routes combine authentication, organisation membership and permission guards. Role-assignment tests cover denied permissions and cross-organisation requests. This illustration describes those controls; it is not proof of complete production isolation.

Illustrative control path
Person / assigned role
Authorised operation boundary
  1. Active membership
  2. Permission check
  3. Permitted document
  4. Review record
No permission → access denied

The illustrated boundary does not assess a live deployment.

02 / Management-system support

Bring standards into
day-to-day work.

Information-security management

Memberships, role permissions and protected document access can support defined responsibilities and access review. Your organisation determines its risks, controls and review process.

  1. ObjectiveManage information risk
  2. RequirementDefine responsibilities
  3. ControlApply access permissions
  4. EvidenceReview roles and records
  5. ReviewAssess effectiveness

High-level illustration, not a validated clause mapping.

Platform support does not itself confer certification. Certification depends on the organisation, its management system and independent assessment.

This describes customer process support, not SeraphCode certification or a complete built-in ISMS or QMS.

03 / Smart Audits

Planned review capability

Find evidence gaps
before the review.

Smart Audits is proposed assisted operational review and audit preparation: bringing requirements, supporting records and follow-up into one reviewable view.

Existing forms, workflow requirements and selected history provide the foundation. Automated gap checks and review queues would be scoped extensions. Evidence present still needs assessment; no example outcome changes when a signal completes.

Illustrative review · No live data
Evidence presentReview required
Expected requirement
Final inspection recorded before release review.
Relevant record
Inspection F-204 · submitted
Observed finding
A record exists; its result and adequacy still need review. Submitted does not mean passed.
Suggested follow-up
Review the result and supporting evidence before considering release.

For human review · Quality reviewer

Continuing review trace / Findings stay unchanged
  1. Required inspection
    RequirementEvidence linkEvidence present
  2. Verification record
    RequirementEvidence linkEvidence missing
  3. Policy review
    RequirementEvidence linkReview required

Interpretation, with human review.

Raziel, the planned decision engine, is designed to help explain gaps, summarise findings and suggest follow-up. Original records remain the evidence. Any future action must respect backend permissions and configured approvals.

Explore Raziel
  1. Evidence
  2. Suggested finding
  3. Human review
  4. Approved follow-up
What this review would—and would not—do

Smart Audits would assist preparation, not perform independent certification, scan for vulnerabilities or guarantee an audit result. Competent reviewers must assess findings. A proposed summary is not original evidence, and AI must not close non-conformances or waive controls.

04 / Deployment / Managed operations

Your infrastructure.
Our operational expertise.

Plan SeraphSuite within your environment or on an agreed cloud platform, with access, maintenance and recovery shaped around your business.

Scoped to your environment

Run the system within your own environment.

We can scope SeraphSuite on infrastructure at your premises, with installation, application updates, monitoring and recovery defined in an agreed management plan.

  • Agreed local application and data hosting
  • Access designed around your business network
  • Maintenance and support within the agreed scope

For organisations needing direct control over infrastructure and how it connects to their operation.

Hardware, dependencies and deployment require assessment and validation.

Illustrative deployment
Your team

Your premises / Local environment

Local business network
SeraphSuite application
Operational dataAccess through the application
Backup & recovery arrangementLocation and restoration plan agreed

Optional support access · agreed & controlled

Managed on-premises. Planning illustration only. Deployment subject to technical assessment.

Managed means responsibilities are defined.

Management scope can include the areas below. Agree who performs each task, when it happens, who responds to alerts, what your team provides and which changes need approval.

Setup & configuration
Application deployment, environment settings and access arrangements.
Updates & change
Planned releases, security updates and approved maintenance.
Monitoring & follow-up
Agreed health checks, alerts and escalation responsibilities.
Backup & recovery
Backup location, retention, checks and restoration testing.

Your team retains responsibility for authorised users, business permissions, devices and internal requirements; local facilities and networks also need clear ownership.

Australian focus.
Room to operate internationally.

We can assess local infrastructure or an appropriate Australian cloud region, checking service availability. International requirements are scoped around your operation. Planning covers primary data, backups, support access and external processing—including integrations and Raziel separately.

Technical details & who looks after what

Who looks after what?

SeraphCode: application deployment and management tasks agreed in the service scope.

Client: authorised users, business permissions, endpoint practices and internal operating requirements; local power, networking and physical access where relevant.

Cloud provider, when used: underlying infrastructure and the responsibilities of the selected services—not SeraphSuite application code or your business access decisions.

The division depends on the design and service agreement. Cloud account ownership, billing and administrative access are agreed; neither party’s ownership is assumed.

Access, protection & change

Define who can sign in, what they can access and how any support access is authorised, limited and reviewed. Remote support is not an unrestricted permanent connection.

Assess separation of application, database and management interfaces, exposing only what is required. Agree and validate protection for data in transit and storage. These are deployment requirements, not guarantees provided by the illustration.

Schedule and review application releases and security patches. Local hardware capacity, replacement and on-site assistance require separate scope decisions.

Recovery that matches the work

Agree backup location, retention, checks and restoration testing. Define how quickly the business needs service restored and how much recent work could need to be recovered.

A backup must be tested for restoration. Replication is not a backup, and neither backups nor multiple locations establish uninterrupted service or automatic failover.

Location is only part of the design

On-premises does not mean offline. Identify external identity, email, integrations, licensing, monitoring and AI dependencies, along with maintenance and support connectivity. Local ERP hosting does not establish local AI processing or that all data stays on-site.

Assess primary and recovery locations, support access and external processing together. Selecting an Australian region does not settle every residency or privacy requirement. Provider certifications do not certify SeraphCode or SeraphSuite.

Provider responsibility references: Microsoft Azure · AWS · AWS data-location guidance. These explain provider boundaries, not our implementation’s security or compliance.

The Australian Privacy Principles and OAIC security guidance inform scoping discussions where relevant. ASD’s Essential Eight is a reference for deployment assessment. Referencing guidance does not establish compliance or a maturity level.

Standards and guidance

These official sources describe the standards and guidance. They do not certify this platform or replace an assessment of your organisation.

Let’s define the controls
your operation needs.

Discuss security and audit requirements