Security control model
Use this model to locate the public technical description of a control area and understand where stronger evidence remains gated.
Scope
The public security control model is a technical projection of the Trust Center
security_posture claim category. The source category describes ClearPoint's
control posture across source-code governance, runtime governance, tenant data
isolation, and audit evidence.
Trust boundary
This page exposes a public control map. Customer-specific configuration, NDA-gated evidence packets, authenticated trust surfaces, secrets, and raw tenant data remain outside the public boundary.
Control objective
The model gives security reviewers a bounded map from each control area to the kind of source and evidence that supports it.
Data handled
The public page handles control descriptions and links between source, runtime, tenant-isolation, secrets, monitoring, and audit-evidence concerns. It does not handle customer payloads or secret values.
Evidence produced
| Area | Public technical summary |
|---|---|
| Source-code governance | Changes are reviewed through the repository governance process, CI, and security scanning before release evidence is recorded. |
| Identity and access | Customer identity flows use the platform authentication model; customer SSO setup is documented in the gated IdP guides. |
| Tenant data isolation | Tenant-scoped data uses row-level tenant boundaries plus application-layer tenant checks, with release evidence tied to the source control model. |
| Secrets | Secret values belong in managed secret stores and must not appear in source, logs, fixtures, or public docs. |
| Security monitoring | Security posture evidence is collected through the operating security program and mapped to Trust Center claim categories. |
| Audit evidence | Material actions produce structured evidence records that can be reviewed without relying on general application logs. |
Limitations
Use this page as the public map for security review. It names the control areas and where their technical evidence belongs; it does not replace customer-specific configuration review, NDA-gated evidence packets, or authenticated product trust surfaces.
Responsibilities
If a security statement needs a stronger customer-facing assertion, it must move
through the Trust Center claim_registry review path before publication.
Source
The authoritative source is the Trust Center security_posture claim category identified by this page's source metadata. The page does not create a separate control claim.
Next steps
Read the audit and evidence model for material-action records or the data handling model for classification boundaries.
Related documentation
See also
Terms used on this page
Report a problem with this page
- Doc ID
cpl.docs.security.controls- Source
cpl-ops:docs/standards/platform-pack/CPL-TRUST-CENTER-CLAIM-REGISTRY-SEED.md#3.8- Updated