One evaluation path from
security review to rollout
SAML SSO, audit-ready evidence exports, and structured procurement materials for organizations where compliance is an operational requirement, not a checkbox exercise.
Built for enterprise review
Trust signals that procurement, legal, and security teams expect to verify before signing.
Security review ready
Procurement materials available on request
Audit-ready exports
Evidence and control context preserved
AU-hosted by default
Additional residency needs reviewed during procurement
Public status visibility
Operational updates and uptime checks published
SAML + MFA
Enterprise identity controls supported
DPA and subprocessor docs
Available for enterprise review
Built for security teams
Every feature designed around enterprise security requirements, compliance obligations, and operational excellence.
SAML 2.0 SSO & MFA Enforcement
Metadata-based SAML 2.0 configuration with major identity providers.
Data Residency Controls
AU-hosted by default with additional residency requirements reviewed during procurement.
Role-Based Access Control
Granular permissions with role-based access controls and audit logging.
Audit-Ready Artifacts
Export complete evidence packages formatted for SOC 2, ISO 27001, and NDIS audits.
Evidence Vault & Version Control
Immutable evidence storage with versioning, SHA-256 integrity verification, and retention policies.
SOC 2 Readiness Engine
Automated readiness scoring with weighted domain analysis and one-click certification reports.
Five-layer security architecture
Every layer independently secured, monitored, and audited, because enterprise compliance demands defense in depth.
Every request must clear all five layers in order. Trace one, or try to skip the gates.
- L1
Application Security
Security headers, input validation, dependency review, and controlled release practices across the platform.
Content Security Policy (CSP)Input validation and sanitizationDependency and vulnerability reviewControlled release and rollback procedures - L2
Authentication & Identity
Enterprise identity controls centered on SAML SSO, MFA enforcement, session policy, and audited role changes.
SAML 2.0 SSOMFA enforcementSession policy controlsAudited role and access changes - L3
Data Protection
AES-256 encryption at rest, TLS 1.3 in transit, export controls, and encrypted backup workflows.
AES-256 encryption at restTLS 1.3 in transitControlled export workflowsEncrypted backup handling - L4
Infrastructure Security
Enterprise cloud hosting with environment separation, backup procedures, and documented operational recovery planning.
AU-hosted default deploymentEnvironment separationBackup and recovery proceduresOperational change controls - L5
Governance & Logging
Immutable audit logs, exportable evidence history, retention controls, and documented incident handling.
Immutable audit trailExportable audit historyConfigurable retention controlsDocumented incident handling
Enterprise service commitments
Operational visibility, structured support paths, and enterprise controls, with specific terms defined during procurement.
Status visibility
Public uptime checks and operational updates
Maintenance notice
Advance notice target for planned maintenance
- Procurement artifactsData processing agreement, trust packet, subprocessor list, and security review materials
- Priority supportA named escalation path for the duration of an active enterprise review
- Data exportSelf-serve audit-ready exports and portability workflows
- Identity controlsSAML 2.0 single sign-on, MFA enforcement, and session policies
How FormaOS is deployed
One deployment model is live today. Anything beyond it is scoped during procurement, so nothing here commits us to infrastructure we do not run.
Multi-tenant AU cloud
How every organisation runs FormaOS today. Shared infrastructure hosted in Australia, with tenant isolation enforced in the database rather than in application code.
Dedicated arrangements
If your review requires stronger separation than the shared platform provides, we scope what is feasible during procurement rather than listing it as shipping.
Security questionnaire
Answers to the questions your procurement, legal, and information security teams need answered before signing.
Enterprise Ready
Start your enterprise evaluation
Request the security review packet, run a proof-of-concept, or bring your procurement team into a structured review. We support the process your organization already follows.

