Enterprise Trust Center
for Faster Security Reviews
Controlled visibility into live compliance posture, evidence integrity, encryption, SSO, data residency, and procurement artifacts for enterprise buyers.
The answers security reviewers ask first
Identity, data handling, and evidence integrity, summarised here and documented in full further down the page.
- Identity and access controls
Enterprise sign-on, MFA enforcement, and accountable approval histories are part of the buying conversation, not an afterthought.
SAML 2.0 SSO · MFA enforcement · Role-aware access reviews
- Data handling and residency posture
Buyers can inspect how evidence, exports, and regulated data move through the system before they request a full vendor packet.
Encrypted storage paths · Residency posture visibility · Documented retention controls
- Evidence integrity and auditability
The trust story is strongest when the platform shows exactly how approvals, artifacts, and exports stay connected in one defensible chain.
Immutable audit trail · Export-ready evidence bundles · Procurement artifact workflow
- NDIS Practice Standards
- Aged Care Quality Standards
- NSQHS Standards
- AHPRA
- ASIC s912A
- APRA CPS 230
- AUSTRAC AML/CTF
- ACECQA NQF
- WHS Act
- SafeWork Australia
- ISO 27001
- SOC 2
- GDPR
- NIST CSF
- PCI DSS
- HIPAA
- CIS Controls
- ISO 9001
Verifiable, not just “we have logs”
The audit log is not a trust-us assertion. Three independent mechanisms have to agree before a record is accepted as untampered, and one of them sits outside our infrastructure entirely.
The log itself
Every row is signed against the one before it
Each audit row carries a sequence number and an HMAC-SHA256 signature over the previous row. A nightly job re-walks the chain end to end. If a row were altered or removed, the walk breaks at that point, and it surfaces as a chain-integrity break before your next audit rather than during it.
The external witness
The chain top is anchored outside our systems, daily
Once a day at 05:30 UTC, each organisation's chain top is submitted to Sigstore Rekor, the Linux Foundation transparency log used for signed open-source releases. The submission is an RFC 6962-style Merkle entry. An auditor can confirm the timestamp of any event through Linux Foundation infrastructure, without taking our word for it.
The database rule
Append-only is enforced by Postgres, not by our code
A BEFORE UPDATE OR DELETE trigger rejects any mutation of an audit row, backed by restrictive row-level security deny policies. An operator holding service-role credentials, which bypass row-level security, is still stopped by the trigger. Because the rule sits in the database, an application-level bypass is not a route around it.
The proof a buyer or auditor needs is in code paths checked into the repository, not in a marketing page. Ask for the anchoring job and the trigger definition during security review and you will get both.
Trust Center sections
Every assurance document a procurement team typically asks for, written for compliance buyers and security reviewers. Each section is a standalone artifact you can share with your team.
Data handling
Storage, encryption, retention, and deletion of customer data.
Data Processing Agreement
GDPR Article 28 and Australian Privacy Act-aligned terms for enterprise customers.
Service Level Agreement
Uptime targets, incident response timelines, and credits.
Sub-processors
Third-party providers that process customer data.
Incident response
How FormaOS detects, contains, and discloses incidents.
Vendor assurance
Independent assessment plan and assurance artifacts.
Procurement
How a review runs: what you receive, how long it takes, and what happens next.
Security Review FAQ
Identity, encryption, isolation, hosting, and the capabilities we do not have.
Vendor trust packet
Bundled review materials covering architecture and assurance.
