Trust through explicit boundaries

Security is a product foundation, not a marketing badge.

This page separates protections implemented on the public website from security and governance capabilities that remain product direction. Ovianza does not claim certifications it has not published evidence for.

Public website baseline

Protections in this site implementation.

These controls are included in the Razor Pages application and can be verified from its responses and container configuration.

Implemented

Strict browser policy

A self-hosted Content Security Policy, anti-framing controls, content-type protection, and a restrictive permissions policy reduce common browser attack paths.

Implemented

No third-party trackers

The site loads its fonts, styles, scripts, and brand art locally and does not include an analytics or advertising tracker.

Implemented

Minimal public surface

The marketing app exposes content, versioned assets, a sitemap, and a health probe. It does not accept credentials or payment details.

Implemented

Immutable deployment path

The included container workflow publishes commit-SHA image tags. The separate GitOps cutover task owns environment promotion and production approval.

Implemented

Non-root runtime

The provided production image is configured to use the ASP.NET non-root application user and the platform-standard internal port.

Suite security direction

Controls that grow with the product.

These are architecture and package directions. They should not be interpreted as generally available features until release evidence and customer documentation say so.

  1. Identity and tenant boundaries

    Shared sign-in, roles, app activation, and tenant-aware access are foundational platform seams.

    Foundation direction
  2. Operational audit and policy

    Audit trails, advanced permissions, data controls, and administrative visibility belong to the growth path.

    Roadmap direction
  3. Enterprise assurances

    SSO, formal compliance evidence, retention commitments, and customer security reviews require explicit release and operational proof.

    Not yet claimed
No implied certification

Claims follow evidence.

Ovianza does not currently claim SOC 2, ISO 27001, HIPAA, PCI DSS, or another formal certification on this site. Those claims will appear only with an owner-approved scope and supporting evidence.

Product access

Evaluate the connected foundation in early access.

Use the onboarding interest path for product access. Do not send secrets or sensitive personal data through the public marketing site.