Identity and MFA
Target customer identity architecture based on Microsoft Entra External ID, with MFA and enterprise federation options governed in the identity layer.
SECURITY & TRUST
This public trust page explains the security model without overstating certifications or exposing sensitive control evidence. Detailed assurance material is available only through controlled customer access.
SECURITY MODEL
Target customer identity architecture based on Microsoft Entra External ID, with MFA and enterprise federation options governed in the identity layer.
Organization membership, subscription status, product entitlement, role, and environment assignment are evaluated independently.
Customer organizations and product data are logically separated, with server-side authorization required for every protected action.
Transport encryption and platform-managed or customer-approved encryption controls protect information in transit and at rest where supported.
Material access, launch, schedule, document, entitlement, and administration events can be recorded with user, organization, outcome, and correlation context.
Source control, dependency review, secrets management, vulnerability remediation, release validation, and controlled deployment practices support the software lifecycle.
Security events are triaged, contained, investigated, documented, and communicated according to severity, legal obligations, and customer commitments.
Backup, restore, service resiliency, and recovery controls are defined by the deployed product architecture and purchased service level.
DocuForge provider routes, regions, retention, data classification, and human review expectations must align with customer-approved configurations.
Privacy, retention, subprocessors, data rights, PHI conditions, and restricted-data limitations are governed by published policies and executed agreements.
COMPLIANCE POSITION
Collablynx is designed around measurable security, privacy, identity, audit, resilience, and data-governance controls that support enterprise and regulated operating environments. Compliance status is communicated at the product and deployment scope actually achieved so customers can evaluate current evidence with confidence.
Collablynx emphasizes least-privilege access, MFA, tenant authorization, encryption, auditability, secure development, incident response, continuity, privacy controls, and governed AI processing. Where a formal framework, certification, authorization, assessment, or contractual program applies—such as HIPAA arrangements, SOC 2, ISO 27001, FedRAMP, CMMC, PCI DSS, CJIS, or HITRUST—Collablynx identifies the exact scope and current status and provides appropriate supporting evidence through controlled customer access.
REGULATED DATA
Collablynx can support regulated-data use cases through explicitly approved product configurations and contractual controls. Protected health information and other regulated or restricted data may be submitted only when the applicable order form, security schedule, data-processing agreement, BAA, or sector-specific addendum authorizes the data type, product boundary, region, provider route, and required safeguards.
Read Privacy & Data Protection Policy →ASSURANCE REQUESTS
Security overview, identity, encryption, privacy, data governance, resilience, responsible disclosure, and verified compliance status.
Security questionnaires, architecture reviews, control mappings, test summaries, continuity evidence, and contractual documents.
Deployment architecture, data classification, region, integration, retention, AI provider, and tenant-specific risk decisions.
ACCESS MODEL
Prospects receive enough detail to evaluate the platform. Sensitive implementation and assurance material stays protected.
NEXT STEP
A tailored product review can cover identity, tenant boundaries, data handling, AI routing, audit evidence, and assurance requirements.