Trust is engineered into everything we build.

Every SUPENTIS platform is designed around security, privacy, resilience, governance, reliability, and responsible innovation — from the very first architectural decision to the last line of deployed code.

Our ArchitectureContact the Trust Team
Security by Architecture
Privacy by Design
Responsible AI
Operational Resilience

Operational Proof Points

Measured reliability across institutional deployments.

All Systems Operational (99.991% Uptime)

99.991%

Measured Annual Uptime

Across active Medleep, Edleep, and Erpleep enterprise customer clusters over past 12 months.

4.2M+

Daily Identity Authorizations

Sub-millisecond RBAC authorizations processed via LeepID zero-trust edge infrastructure.

120+

Institutional Deployments

Hospitals, health networks, universities, and enterprise organizations operating on SUPENTIS.

0

Data Isolation Breach Incidents

Zero cross-tenant data isolation or cryptographic key compromise incidents reported to date.

Architecture & Security White Papers

Download independent security audit summaries and zero-trust architectural reviews.

View Security ArchitectureRequest SOC 2 Report

Trust Philosophy

Trust cannot be claimed. It must be demonstrated.

Institutions that depend on SUPENTIS platforms are placing their operational continuity, their sensitive data, and in many cases their patients and students, in our hands. That responsibility is not treated lightly.

Trust requires discipline — in how systems are designed, how code is written, how incidents are handled, and how data is treated. Trust requires transparency — publishing what we do and how we do it, rather than asking organizations to assume. Trust requires consistency — because a single failure can undo years of reliable performance.

This page explains how SUPENTIS earns and maintains the trust of the institutions it serves — not through assertions, but through engineering decisions, operational practices, and organizational principles that make dependability a structural property of every platform we build.

Discipline

Every engineering decision is made with long-term reliability as an explicit requirement — not as an afterthought.

Transparency

We publish how our systems work, how incidents are handled, and how data is protected — because trust cannot exist without visibility.

Consistency

Security, privacy, and reliability are not applied case-by-case. They are architectural properties applied uniformly across every platform.

Accountability

When things go wrong — and in complex systems, they occasionally do — we take responsibility, communicate clearly, and improve permanently.

Security

Security by architecture. Not by addition.

Security features added after a system is built are inherently weaker than security designed into a system from the beginning. Every SUPENTIS platform begins with security as a structural requirement — not a feature to be implemented later.

The controls below are not a list of capabilities. They are descriptions of how the platform is built.

Identity-First Architecture

Every request, at every layer of the platform, is authenticated and authorised before any data is accessed. Identity is not a gate at the front door — it is verified throughout the entire request lifecycle.

Least Privilege

Users, services, and processes are granted only the permissions required for their specific function. Nothing more. Privilege escalation requires explicit authorisation and is fully audited.

Role-Based Access Control

Access to institutional data is governed by role, organisational hierarchy, and contextual policy. Roles are defined, versioned, and auditable — ensuring that access reflects current organisational reality.

Zero Trust Principles

No user, device, or service is trusted by virtue of its location inside the network. Every interaction is verified. Internal traffic is treated with the same scrutiny as external requests.

Encryption Throughout

Data is encrypted in transit using TLS 1.3 and encrypted at rest using AES-256. Encryption keys are managed through dedicated key management services with regular rotation policies.

Complete Auditability

Every data access, permission change, and administrative action is recorded in tamper-resistant audit logs. Institutional administrators have access to comprehensive audit trails for their environment.

Data Isolation

Institutional data is isolated at multiple levels — tenant, service, and database. Cross-tenant access is architecturally impossible, not merely policy-prohibited.

Secure Defaults

Every SUPENTIS platform ships in its most secure configuration. Security must be intentionally reduced — it can never be accidentally omitted. The default state is always the most secure state.

Privacy

Privacy as an organizational commitment.

The institutions that use SUPENTIS platforms manage some of the most sensitive data that exists — patient records, student profiles, financial information, workforce data. Privacy is not a legal checkbox for us. It is a responsibility.

"Visitors should feel respected. Not monitored."

You Own Your Data

Data created inside a SUPENTIS platform belongs to the institution that created it. SUPENTIS has no claim to institutional data. It is available for export in standard formats at any time.

Minimal Collection

We collect only the data necessary to deliver the service. We do not collect data speculatively or for purposes beyond what institutions have explicitly authorised.

Transparent Processing

Every category of data processing is documented. Institutions know what data is processed, why, where it is stored, and how long it is retained.

Consent Architecture

Where individual consent is required — particularly in healthcare and education contexts — the platform includes consent management capabilities that honour user choices at every level.

Privacy by Design

Privacy is not a control added on top of the platform. It is a design principle that shapes every data model, every API, every interface, and every integration from the initial architecture.

International Principles

Our privacy architecture is aligned with international privacy principles. As specific regulatory frameworks apply to particular institutions, we work with those institutions to ensure compliance.

Reliability & Availability

Operational resilience designed from the ground up.

Institutions cannot afford downtime. Clinical systems that are unavailable affect patient care. Educational systems that fail during examinations create institutional crises. SUPENTIS engineering treats availability as a fundamental requirement — not a target on a dashboard.

Redundancy

Critical platform components operate across redundant infrastructure. Single points of failure are identified during architecture review and eliminated before deployment. No production system relies on a single instance of any critical service.

Continuous Monitoring

Platform health is monitored continuously across infrastructure, application, and security layers. Anomalies trigger automated responses before they become incidents — and on-call engineering teams are alerted to anything that warrants human attention.

Incident Response

When incidents occur, documented response procedures activate within minutes. Institutional administrators receive clear, timely communication. Post-incident reviews identify root causes and drive permanent systemic improvements.

Disaster Recovery

Recovery point objectives and recovery time objectives are defined for every platform service. Regular recovery testing validates that these targets are achievable — not just documented aspirations.

Backup Strategy

Data is backed up continuously. Backups are encrypted, geographically distributed, and regularly tested for integrity and restorability. Backup processes are monitored with the same rigour as production systems.

Resilience Engineering

Systems are designed to degrade gracefully rather than fail completely. When a component experiences difficulty, the platform continues to function at reduced capacity rather than presenting a complete outage to users.

Business continuity is not a feature. It is a structural property of how SUPENTIS platforms are built.

A future operational status dashboard will provide real-time visibility into platform health. Institutional administrators will be able to view current status, incident history, and scheduled maintenance windows at any time.

Responsible AI

AI as a carefully governed capability.

Artificial intelligence in institutional environments carries real consequences. A clinical AI that produces incorrect recommendations affects patient safety. An educational AI with hidden biases affects student outcomes. SUPENTIS treats AI governance with the same seriousness as security architecture.

The goal is not to avoid AI. It is to ensure that every AI capability deployed inside a SUPENTIS platform meets the standard that institutions and the people they serve deserve.

Human Oversight

AI in SUPENTIS platforms augments human decision-making. It does not replace it. Every AI-assisted decision remains subject to human review, challenge, and override.

Transparency

When AI contributes to a recommendation or decision, users know. There are no hidden algorithms making consequential decisions without institutional awareness.

Explainability

AI outputs in institutional contexts must be explainable — particularly in clinical and educational settings where decisions affect individual outcomes. We avoid black-box models where explanation is required.

Bias Awareness

AI systems are evaluated for bias during development and monitored in deployment. Particularly in healthcare and education, differential outcomes across population groups are treated as critical quality failures.

Clinical Responsibility

AI in clinical environments operates under the clinical governance of the institution. SUPENTIS provides the capability. The institution provides the clinical oversight. This division of responsibility is architectural, not contractual.

Educational Integrity

AI in educational environments supports the work of educators and students. It does not substitute for the educational relationship or compromise the academic integrity of assessment.

AI Governance

Every AI capability deployed in a SUPENTIS platform is reviewed by an internal AI governance process before it reaches a production environment. Approval requires documented transparency, defined oversight, and agreed performance criteria.

Ethical Development

AI development at SUPENTIS follows a set of ethical development principles that govern research, selection of training data, model evaluation, deployment criteria, and ongoing monitoring.

Compliance & Governance

Governance as culture. Not certification.

Certifications document a point in time. Governance culture produces consistent outcomes over years. SUPENTIS invests in the internal practices, review processes, and engineering disciplines that make compliance a natural result — not a periodic exercise.

Specific compliance documentation is available to institutions as part of the onboarding process and through the Trust Centre upon request.

Security Review Board

Every significant platform change undergoes security review before release. The review process is independent of the team that built the change.

Engineering Standards

Code quality standards, security coding guidelines, and architectural principles are documented, enforced through peer review, and updated as best practice evolves.

Quality Reviews

Automated and manual quality gates are applied at every stage of the development pipeline. Code cannot reach production without passing defined quality thresholds.

Risk Management

Risks to platform security, availability, and data integrity are formally identified, assessed, and managed. Risk decisions are documented and revisited regularly.

Operational Policies

Documented policies govern every operational function — from how access is provisioned to how incidents are classified, escalated, and resolved.

Continuous Improvement

Governance processes are not static. Every incident, every audit finding, and every near-miss generates improvement actions that are tracked to completion.

Regulatory Readiness

The platform architecture is designed to accommodate specific regulatory requirements — HIPAA, GDPR, and sector-specific frameworks — as institutions require them.

Vendor Governance

Third-party vendors and service providers who process institutional data are subject to the same security and privacy standards as SUPENTIS internal systems.

Accessibility

Accessibility is part of engineering quality.

Institutions serve people with a wide range of abilities, needs, and assistive technologies. An institutional platform that is inaccessible is one that fails a portion of the population it exists to serve. For SUPENTIS, accessibility is permanent — not optional.

"Every person who interacts with a SUPENTIS platform should be able to do so fully — regardless of ability, device, or context."

WCAG 2.1 AA Compliance

Every SUPENTIS interface is built to meet WCAG 2.1 AA standards as a baseline. Accessibility testing is part of the quality assurance process — not a separate audit conducted after release.

Keyboard Navigation

Every function in every SUPENTIS interface is fully operable via keyboard. Institutional users who rely on keyboard navigation can perform every task without a pointing device.

Screen Reader Support

Platform interfaces are built with semantic HTML and ARIA attributes that work correctly with leading screen reader technologies across web and mobile environments.

Reduced Motion

Users who experience discomfort from motion effects can rely on the platform respecting the `prefers-reduced-motion` media query across all animated interface elements.

Colour & Contrast

All interface text meets minimum contrast ratios. Colour is never the sole means of communicating information. Interfaces are tested for accessibility under multiple colour vision conditions.

Enterprise Usability

Accessibility and usability are not separate concerns. The same design discipline that produces accessible interfaces also produces efficient, low-friction workflows for all institutional users.

Quality Assurance

Quality as culture. Not process.

Engineering discipline at SUPENTIS is not enforced by process alone. It is sustained by a culture in which every engineer takes personal responsibility for the quality of what they build and the reliability of what they release.

01

Peer Review

No code reaches production without review by at least one other engineer. Security-sensitive changes require review by a designated security reviewer.

02

Automated Testing

Comprehensive automated test suites cover unit behaviour, integration contracts, and end-to-end workflows. Tests run on every change, on every branch, before any code is merged.

03

Security Testing

Static analysis for security vulnerabilities runs automatically on every commit. Dependency scanning identifies known vulnerabilities in third-party libraries. Penetration testing is conducted on a scheduled basis.

04

Performance Testing

Performance testing validates that the platform meets response time and throughput targets under realistic load conditions — including the extreme load spikes that educational institutions experience during examination periods.

05

Regression Testing

Every release is validated against a comprehensive regression suite before deployment. Existing behaviour is protected. Changes that break existing functionality are rejected before they reach any environment.

06

Manual Testing

Automated testing cannot replace human judgement. Manual exploratory testing evaluates edge cases, user experience quality, and behaviours that are difficult to specify in automated tests.

07

Release Management

Releases are planned, documented, and deployed using automated pipelines that enforce quality gates at every stage. Rollback procedures are defined and tested before any release reaches production.

08

Continuous Improvement

Quality metrics are tracked over time. Test coverage, defect rates, incident frequency, and time-to-resolution inform a continuous improvement programme that raises the quality bar with every release cycle.

Operational Transparency

Institutions deserve visibility into the systems they depend on.

Transparency is not just a value — it is an operational commitment. Institutions that depend on SUPENTIS platforms will have access to real-time status information, incident history, and scheduled maintenance windows through a dedicated operational transparency dashboard.

Platform Status

All Systems Operational

LIVE
Core Platform
Operational
Identity & Access
Operational
Data Services
Operational
Notification Engine
Operational
AI Services
Operational
Integration Layer
Operational

Incident History

Complete history of platform incidents, including root cause analysis and resolution timelines.

Coming Soon

Maintenance Windows

Advance notice of scheduled maintenance, with expected impact and duration clearly communicated.

Coming Soon

Security Advisories

Security advisories issued to institutional administrators when relevant vulnerabilities are identified or addressed.

Coming Soon

Release Notes

Detailed release notes published with every platform update, including security changes and new capabilities.

Coming Soon

Shared Responsibility

Security is a shared model. Transparency serves everyone.

Understanding what SUPENTIS protects and what remains the institution's responsibility enables effective security posture for both parties. Clarity here prevents gaps — and gaps are where incidents occur.

SUPENTIS Responsibility

What we protect.

Platform security architecture and secure defaults

Encryption of data in transit and at rest

Infrastructure security and patch management

AI governance and responsible AI controls

Availability and disaster recovery of the platform

Security of the platform codebase and dependencies

Audit logging infrastructure and tamper resistance

Security monitoring and threat detection at the platform level

Institution Responsibility

What you manage.

Administrative account management and credential hygiene

Role assignment and access provisioning for institution staff

Device security for devices used to access the platform

Governance of integration credentials and API keys

Training staff on security practices and awareness

Reporting suspected security incidents promptly

Managing exported data in customer-controlled environments

Institutional governance policies for platform usage

Security Research

Security as an active discipline.

Security is not a state that is achieved and maintained passively. It requires active research, continuous testing, and a culture that treats vulnerability discovery as valuable — regardless of its source.

Penetration Testing

SUPENTIS platforms undergo regular penetration testing by qualified security professionals. Testing covers network, application, and infrastructure attack surfaces. Results drive remediation actions tracked to closure.

Vulnerability Disclosure

SUPENTIS maintains a responsible disclosure programme. Security researchers who identify vulnerabilities in our platforms are invited to report them through a defined channel. All reports are acknowledged, investigated, and resolved in accordance with our disclosure policy.

Threat Modelling

Security threats are modelled during the design phase of every significant platform capability. Threat models are reviewed by security engineers and inform the security controls built into the implementation.

Security Publications

Security research findings that can be shared without creating risk are published through the SUPENTIS Research Centre — contributing to the wider security knowledge of the enterprise technology community.

Bug Bounty Programme

A formal bug bounty programme is planned for future launch. When established, it will invite the security research community to assist in the ongoing identification of vulnerabilities across the SUPENTIS platform ecosystem.

Responsible Disclosure

Found a security vulnerability?

We take all security reports seriously. Please do not disclose vulnerabilities publicly before giving us the opportunity to investigate and resolve them. Contact the security team directly.

Report a Vulnerability

Frequently Asked Questions

Answers to the questions institutions ask most.

Contact the Trust Team

The right team. The right conversation.

Trust enquiries deserve dedicated attention — not a general support queue. Each of the channels below connects directly to the team responsible for the subject you are raising.

Security Questions

Questions about platform security architecture, controls, or security posture.

security@supentis.com

Privacy Requests

Data subject access requests, deletion requests, or privacy enquiries under applicable regulations.

privacy@supentis.com

Compliance Enquiries

Questions about regulatory compliance, governance documentation, or certification status.

compliance@supentis.com

Responsible Disclosure

Reporting a security vulnerability or potential issue in any SUPENTIS platform or service.

security@supentis.com

Accessibility Feedback

Reporting an accessibility barrier or requesting assistance with accessing SUPENTIS platforms.

accessibility@supentis.com

Trust Partnerships

Research collaboration, institutional trust assessments, or joint governance initiatives.

Contact Us

All Trust Centre enquiries are acknowledged within one business day. Security and privacy matters are treated with urgency. The Trust team operates independently of the commercial organisation.