Dedicated customer environment
Each customer is designed to receive a separate service desk project with its own application services, database, cache, and knowledge environment.
Security
Stand Easy Ops is being built around customer isolation, scoped access, careful handling of secrets, and human approval before system-changing actions.
Current status: Stand Easy Ops Agent Desk is pre-launch. This page describes the production architecture and operating baseline being built. It does not claim an independent audit, security certification, or control that has not yet been put into operation.
Security controls should be practical, testable, and matched to the riskānot buried in marketing language.
Each customer is designed to receive a separate service desk project with its own application services, database, cache, and knowledge environment.
Customer knowledge is stored per customer. Database controls and isolation tests are designed to refuse content carrying another customer's identifier.
System-changing actions are designed to stop for a named operator to review and approve. Investigation and drafting do not imply authority to make a change.
Runtime access is designed around short-lived signed sessions, explicit roles, customer scope, and fail-closed checks when access or entitlement is missing.
Credentials and signing keys are designed to stay in controlled runtime configuration, not source code. Customer services do not need public database ports.
The production baseline includes encrypted per-customer database backups, infrastructure snapshots, retention controls, and restore practice on disposable environments.
A customer deployment is designed as its own project rather than a shared inbox with mixed customer knowledge. The desk, database, knowledge store, agent configuration, and cloud connections are scoped to that customer.
Protected runtime routes are designed to require signed, time-limited credentials with an explicit customer and role. Suspended access and invalid, expired, or incorrectly scoped credentials fail closed.
CloudOps access is an explicit add-on, not an assumed capability. Connections and allowed tools are scoped during onboarding. A missing entitlement does not expose cloud tools, and system-changing operations require the approval path agreed with the customer.
The production baseline includes TLS, managed web-application firewall rules, OWASP-aligned protections, request rate limits, origin checks, and verified webhook signatures where integrations support them. Rules are reviewed before moving from observation to blocking.
Per-customer service desk and knowledge databases are designed to be backed up separately, encrypted before object storage, and retained under a defined lifecycle. Restore procedures are practised away from live customer environments.
Before onboarding, we document the providers needed to deliver the agreed service and the data each provider processes. Applicable hosting location, model-provider terms, and customer requirements are confirmed in the customer agreement.
Stand Easy Ops does not currently claim ISO 27001, SOC 2, or another independent security certification. If that changes, this page will name the certification, scope, and evidence rather than implying coverage.
Send a concise description to [email protected] with the subject Security concern. Do not include passwords, access tokens, private keys, or customer data in the first message.
We will acknowledge the report, establish a safe way to exchange any sensitive detail, and keep you informed while it is investigated.
Tell us what your organisation needs to assess. We can discuss architecture, customer isolation, cloud access, and the controls relevant to your proposed service.
Talk to us about security