Skip to main content

Security

Security and deployment responsibilities

Security requires both application controls and a reviewed deployment. The capabilities below describe the software; configuration, operating policies and responsibilities must be assessed for each institution.

Authentication and role-based access

Bastion includes authenticator-based two-factor authentication support and role-restricted operational interfaces. Roles separate responsibilities such as administration, accounting and compliance review.

Authentication methods, channel-specific behavior, session policies and enforcement requirements need to be verified in the chosen deployment. Support for a control does not mean the same policy is enabled for every user and channel.

Operational audit and access to history

Audit events can associate an action with its actor, affected entities, timestamp and recorded changes. Role-restricted operational views and scoped customer login history support investigation without exposing the same information to every audience.

Event coverage, retention periods, access to sensitive records and any required export or preservation controls should be reviewed against the institution’s policies.

Operational visibility

Service-health checks and monitoring dashboard integration support operational visibility. Processing stages and recorded transaction references help teams investigate work in progress and reconcile results.

Monitoring coverage, alert routing, incident ownership and support arrangements belong in the deployment agreement. These software capabilities are not a statement of round-the-clock staffing or a response-time guarantee.

Review the deployment, not just the feature list

Shared cloud, dedicated cloud, customer-owned cloud and on-premises models assign responsibilities differently. A security review should establish the controls and evidence required for the selected environment.

  • Encryption in transit and at rest, key ownership and access to secrets
  • Network boundaries, environment separation and privileged access
  • Backup scope, retention, restoration testing and agreed recovery objectives
  • Incident handling, monitoring responsibilities and escalation contacts
  • Data location, retention, deletion and approved third-party processing