concept · securityPublicVersion current

Security control model

Use this model to locate the public technical description of a control area and understand where stronger evidence remains gated.

Scope

The public security control model is a technical projection of the Trust Center security_posture claim category. The source category describes ClearPoint's control posture across source-code governance, runtime governance, tenant data isolation, and audit evidence.

Trust boundary

This page exposes a public control map. Customer-specific configuration, NDA-gated evidence packets, authenticated trust surfaces, secrets, and raw tenant data remain outside the public boundary.

Control objective

The model gives security reviewers a bounded map from each control area to the kind of source and evidence that supports it.

Data handled

The public page handles control descriptions and links between source, runtime, tenant-isolation, secrets, monitoring, and audit-evidence concerns. It does not handle customer payloads or secret values.

Evidence produced

AreaPublic technical summary
Source-code governanceChanges are reviewed through the repository governance process, CI, and security scanning before release evidence is recorded.
Identity and accessCustomer identity flows use the platform authentication model; customer SSO setup is documented in the gated IdP guides.
Tenant data isolationTenant-scoped data uses row-level tenant boundaries plus application-layer tenant checks, with release evidence tied to the source control model.
SecretsSecret values belong in managed secret stores and must not appear in source, logs, fixtures, or public docs.
Security monitoringSecurity posture evidence is collected through the operating security program and mapped to Trust Center claim categories.
Audit evidenceMaterial actions produce structured evidence records that can be reviewed without relying on general application logs.

Limitations

Use this page as the public map for security review. It names the control areas and where their technical evidence belongs; it does not replace customer-specific configuration review, NDA-gated evidence packets, or authenticated product trust surfaces.

Responsibilities

If a security statement needs a stronger customer-facing assertion, it must move through the Trust Center claim_registry review path before publication.

Source

The authoritative source is the Trust Center security_posture claim category identified by this page's source metadata. The page does not create a separate control claim.

Next steps

Read the audit and evidence model for material-action records or the data handling model for classification boundaries.

Terms used on this page

Report a problem with this page

Do not include secrets or customer data.


Doc ID
cpl.docs.security.controls
Source
cpl-ops:docs/standards/platform-pack/CPL-TRUST-CENTER-CLAIM-REGISTRY-SEED.md#3.8
Updated