Trust & security · available today

Evidence is sensitive by definition. We treat it that way.

Tenants need proof that their data cannot leak across the boundary and that malicious uploads cannot enter the platform. Netallion isolates every tenant, scans every file before it is accepted, and produces exports you can hand to an auditor with a verifiable manifest.

How it works

Isolation, scanning, verifiable export

Security posture stated precisely — no more than we prove, and no less.

Multi-tenant isolation

Every organisation’s data is isolated at the data layer with row/predicate isolation, and that isolation is re-proven on every change in CI — the application’s database role cannot bypass it, and a query without an established organisation context returns nothing.

Mandatory malware scanning

Every uploaded file passes mandatory malware scanning before it is accepted. A file that fails is rejected at the door — it never lands in your evidence set.

Audit export + SHA-256 manifest

Readiness positions export to an audit ZIP with a SHA-256 manifest, so the recipient can verify the package is internally self-consistent and unaltered in transit.

What you see

Inside the audit export package

When you export, you get a structured package a recipient can open and verify — not a screenshot or a loose PDF.

Product screenshot
The export package — a readiness report, evidence index and Statement of Applicability, bundled in an audit ZIP with a SHA-256 integrity manifest.

Readiness report

The readiness conclusion against a defined scope, labelled with the highest review level it actually reached — never above it.

Evidence index

Every evidence item in scope, with its owner, type and expiry — the register a reviewer works from.

Statement of Applicability

Which requirements are in scope and why, so the boundary of the assessment is explicit.

SHA-256 integrity manifest

A hash for the package contents, so the recipient can verify it is internally self-consistent and unaltered in transit.

The packaging and integrity manifest are live today. The contents of an assessed readiness report depend on activation; the structure that carries it does not.

What comes out

A posture you can put in a security review

Per-tenant isolation enforced at the data layer and re-proven on every change; a scanned, rejected-on-malware upload path; and a self-consistent, SHA-256-manifested export package.

Stated precisely

Isolation is stated as row/predicate isolation proven in CI — we do not claim end-to-end byte-exfiltration testing. Exports are internally consistent, not guaranteed complete against a live evidence set. The general audit log is append-only.

Readiness, not certification. Netallion provides evidence assurance and readiness assessment; it does not issue or guarantee any formal outcome. Where a framework has a formal certification, attestation, authorisation or conformity-assessment scheme, that outcome remains with the appropriately authorised third party or authority. Where the boundary sits.

Take our posture into your security review

Book a walkthrough of tenant isolation, upload scanning and verifiable audit export — available today.