Deny-by-default permissions
API actions are explicitly mapped to roles rather than inferred from page names or client behaviour.
Aperture Flow is designed around least-privilege access, business-unit isolation, authenticated audit history and controlled document processing on Microsoft Azure.
Security claims are limited to product capabilities and deployment design. Formal certifications are not claimed unless independently achieved.
API actions are explicitly mapped to roles rather than inferred from page names or client behaviour.
Document access is restricted by assigned company, division, dealership or operational unit.
History records derive the acting identity from the signed-in session, not browser-supplied names.
Approved and exported records can be locked while genuine validation work remains editable.
Uploads are checked against expected file signatures and processing constraints before extraction.
Capture, edits, decisions, approvals, exports and operational exceptions remain traceable.
The current deployment is hosted using Microsoft Azure App Service, with deployment architecture adapted to the customer's agreed environment and requirements.
Yes. Users can be restricted to assigned business units and only access documents belonging to those authorised areas.
The platform records material document actions, edits, decisions and exports using the authenticated user identity.
No. Aperture Flow does not present formal certification claims unless those certifications have actually been obtained and can be evidenced.