Operational Proof Points
Measured reliability across institutional deployments.
99.991%
Measured Annual Uptime
Across active Medleep, Edleep, and Erpleep enterprise customer clusters over past 12 months.
4.2M+
Daily Identity Authorizations
Sub-millisecond RBAC authorizations processed via LeepID zero-trust edge infrastructure.
120+
Institutional Deployments
Hospitals, health networks, universities, and enterprise organizations operating on SUPENTIS.
0
Data Isolation Breach Incidents
Zero cross-tenant data isolation or cryptographic key compromise incidents reported to date.
Architecture & Security White Papers
Download independent security audit summaries and zero-trust architectural reviews.
Trust Philosophy
Trust cannot be claimed. It must be demonstrated.
Institutions that depend on SUPENTIS platforms are placing their operational continuity, their sensitive data, and in many cases their patients and students, in our hands. That responsibility is not treated lightly.
Trust requires discipline — in how systems are designed, how code is written, how incidents are handled, and how data is treated. Trust requires transparency — publishing what we do and how we do it, rather than asking organizations to assume. Trust requires consistency — because a single failure can undo years of reliable performance.
This page explains how SUPENTIS earns and maintains the trust of the institutions it serves — not through assertions, but through engineering decisions, operational practices, and organizational principles that make dependability a structural property of every platform we build.
Discipline
Every engineering decision is made with long-term reliability as an explicit requirement — not as an afterthought.
Transparency
We publish how our systems work, how incidents are handled, and how data is protected — because trust cannot exist without visibility.
Consistency
Security, privacy, and reliability are not applied case-by-case. They are architectural properties applied uniformly across every platform.
Accountability
When things go wrong — and in complex systems, they occasionally do — we take responsibility, communicate clearly, and improve permanently.
Security
Security by architecture. Not by addition.
Security features added after a system is built are inherently weaker than security designed into a system from the beginning. Every SUPENTIS platform begins with security as a structural requirement — not a feature to be implemented later.
The controls below are not a list of capabilities. They are descriptions of how the platform is built.
Identity-First Architecture
Every request, at every layer of the platform, is authenticated and authorised before any data is accessed. Identity is not a gate at the front door — it is verified throughout the entire request lifecycle.
Least Privilege
Users, services, and processes are granted only the permissions required for their specific function. Nothing more. Privilege escalation requires explicit authorisation and is fully audited.
Role-Based Access Control
Access to institutional data is governed by role, organisational hierarchy, and contextual policy. Roles are defined, versioned, and auditable — ensuring that access reflects current organisational reality.
Zero Trust Principles
No user, device, or service is trusted by virtue of its location inside the network. Every interaction is verified. Internal traffic is treated with the same scrutiny as external requests.
Encryption Throughout
Data is encrypted in transit using TLS 1.3 and encrypted at rest using AES-256. Encryption keys are managed through dedicated key management services with regular rotation policies.
Complete Auditability
Every data access, permission change, and administrative action is recorded in tamper-resistant audit logs. Institutional administrators have access to comprehensive audit trails for their environment.
Data Isolation
Institutional data is isolated at multiple levels — tenant, service, and database. Cross-tenant access is architecturally impossible, not merely policy-prohibited.
Secure Defaults
Every SUPENTIS platform ships in its most secure configuration. Security must be intentionally reduced — it can never be accidentally omitted. The default state is always the most secure state.
Privacy
Privacy as an organizational commitment.
The institutions that use SUPENTIS platforms manage some of the most sensitive data that exists — patient records, student profiles, financial information, workforce data. Privacy is not a legal checkbox for us. It is a responsibility.
"Visitors should feel respected. Not monitored."
You Own Your Data
Data created inside a SUPENTIS platform belongs to the institution that created it. SUPENTIS has no claim to institutional data. It is available for export in standard formats at any time.
Minimal Collection
We collect only the data necessary to deliver the service. We do not collect data speculatively or for purposes beyond what institutions have explicitly authorised.
Transparent Processing
Every category of data processing is documented. Institutions know what data is processed, why, where it is stored, and how long it is retained.
Consent Architecture
Where individual consent is required — particularly in healthcare and education contexts — the platform includes consent management capabilities that honour user choices at every level.
Privacy by Design
Privacy is not a control added on top of the platform. It is a design principle that shapes every data model, every API, every interface, and every integration from the initial architecture.
International Principles
Our privacy architecture is aligned with international privacy principles. As specific regulatory frameworks apply to particular institutions, we work with those institutions to ensure compliance.
Reliability & Availability
Operational resilience designed from the ground up.
Institutions cannot afford downtime. Clinical systems that are unavailable affect patient care. Educational systems that fail during examinations create institutional crises. SUPENTIS engineering treats availability as a fundamental requirement — not a target on a dashboard.
Redundancy
Critical platform components operate across redundant infrastructure. Single points of failure are identified during architecture review and eliminated before deployment. No production system relies on a single instance of any critical service.
Continuous Monitoring
Platform health is monitored continuously across infrastructure, application, and security layers. Anomalies trigger automated responses before they become incidents — and on-call engineering teams are alerted to anything that warrants human attention.
Incident Response
When incidents occur, documented response procedures activate within minutes. Institutional administrators receive clear, timely communication. Post-incident reviews identify root causes and drive permanent systemic improvements.
Disaster Recovery
Recovery point objectives and recovery time objectives are defined for every platform service. Regular recovery testing validates that these targets are achievable — not just documented aspirations.
Backup Strategy
Data is backed up continuously. Backups are encrypted, geographically distributed, and regularly tested for integrity and restorability. Backup processes are monitored with the same rigour as production systems.
Resilience Engineering
Systems are designed to degrade gracefully rather than fail completely. When a component experiences difficulty, the platform continues to function at reduced capacity rather than presenting a complete outage to users.
Business continuity is not a feature. It is a structural property of how SUPENTIS platforms are built.
A future operational status dashboard will provide real-time visibility into platform health. Institutional administrators will be able to view current status, incident history, and scheduled maintenance windows at any time.
Responsible AI
AI as a carefully governed capability.
Artificial intelligence in institutional environments carries real consequences. A clinical AI that produces incorrect recommendations affects patient safety. An educational AI with hidden biases affects student outcomes. SUPENTIS treats AI governance with the same seriousness as security architecture.
The goal is not to avoid AI. It is to ensure that every AI capability deployed inside a SUPENTIS platform meets the standard that institutions and the people they serve deserve.
Human Oversight
AI in SUPENTIS platforms augments human decision-making. It does not replace it. Every AI-assisted decision remains subject to human review, challenge, and override.
Transparency
When AI contributes to a recommendation or decision, users know. There are no hidden algorithms making consequential decisions without institutional awareness.
Explainability
AI outputs in institutional contexts must be explainable — particularly in clinical and educational settings where decisions affect individual outcomes. We avoid black-box models where explanation is required.
Bias Awareness
AI systems are evaluated for bias during development and monitored in deployment. Particularly in healthcare and education, differential outcomes across population groups are treated as critical quality failures.
Clinical Responsibility
AI in clinical environments operates under the clinical governance of the institution. SUPENTIS provides the capability. The institution provides the clinical oversight. This division of responsibility is architectural, not contractual.
Educational Integrity
AI in educational environments supports the work of educators and students. It does not substitute for the educational relationship or compromise the academic integrity of assessment.
AI Governance
Every AI capability deployed in a SUPENTIS platform is reviewed by an internal AI governance process before it reaches a production environment. Approval requires documented transparency, defined oversight, and agreed performance criteria.
Ethical Development
AI development at SUPENTIS follows a set of ethical development principles that govern research, selection of training data, model evaluation, deployment criteria, and ongoing monitoring.
Compliance & Governance
Governance as culture. Not certification.
Certifications document a point in time. Governance culture produces consistent outcomes over years. SUPENTIS invests in the internal practices, review processes, and engineering disciplines that make compliance a natural result — not a periodic exercise.
Specific compliance documentation is available to institutions as part of the onboarding process and through the Trust Centre upon request.
Security Review Board
Every significant platform change undergoes security review before release. The review process is independent of the team that built the change.
Engineering Standards
Code quality standards, security coding guidelines, and architectural principles are documented, enforced through peer review, and updated as best practice evolves.
Quality Reviews
Automated and manual quality gates are applied at every stage of the development pipeline. Code cannot reach production without passing defined quality thresholds.
Risk Management
Risks to platform security, availability, and data integrity are formally identified, assessed, and managed. Risk decisions are documented and revisited regularly.
Operational Policies
Documented policies govern every operational function — from how access is provisioned to how incidents are classified, escalated, and resolved.
Continuous Improvement
Governance processes are not static. Every incident, every audit finding, and every near-miss generates improvement actions that are tracked to completion.
Regulatory Readiness
The platform architecture is designed to accommodate specific regulatory requirements — HIPAA, GDPR, and sector-specific frameworks — as institutions require them.
Vendor Governance
Third-party vendors and service providers who process institutional data are subject to the same security and privacy standards as SUPENTIS internal systems.
Accessibility
Accessibility is part of engineering quality.
Institutions serve people with a wide range of abilities, needs, and assistive technologies. An institutional platform that is inaccessible is one that fails a portion of the population it exists to serve. For SUPENTIS, accessibility is permanent — not optional.
"Every person who interacts with a SUPENTIS platform should be able to do so fully — regardless of ability, device, or context."
WCAG 2.1 AA Compliance
Every SUPENTIS interface is built to meet WCAG 2.1 AA standards as a baseline. Accessibility testing is part of the quality assurance process — not a separate audit conducted after release.
Keyboard Navigation
Every function in every SUPENTIS interface is fully operable via keyboard. Institutional users who rely on keyboard navigation can perform every task without a pointing device.
Screen Reader Support
Platform interfaces are built with semantic HTML and ARIA attributes that work correctly with leading screen reader technologies across web and mobile environments.
Reduced Motion
Users who experience discomfort from motion effects can rely on the platform respecting the `prefers-reduced-motion` media query across all animated interface elements.
Colour & Contrast
All interface text meets minimum contrast ratios. Colour is never the sole means of communicating information. Interfaces are tested for accessibility under multiple colour vision conditions.
Enterprise Usability
Accessibility and usability are not separate concerns. The same design discipline that produces accessible interfaces also produces efficient, low-friction workflows for all institutional users.
Quality Assurance
Quality as culture. Not process.
Engineering discipline at SUPENTIS is not enforced by process alone. It is sustained by a culture in which every engineer takes personal responsibility for the quality of what they build and the reliability of what they release.
Peer Review
No code reaches production without review by at least one other engineer. Security-sensitive changes require review by a designated security reviewer.
Automated Testing
Comprehensive automated test suites cover unit behaviour, integration contracts, and end-to-end workflows. Tests run on every change, on every branch, before any code is merged.
Security Testing
Static analysis for security vulnerabilities runs automatically on every commit. Dependency scanning identifies known vulnerabilities in third-party libraries. Penetration testing is conducted on a scheduled basis.
Performance Testing
Performance testing validates that the platform meets response time and throughput targets under realistic load conditions — including the extreme load spikes that educational institutions experience during examination periods.
Regression Testing
Every release is validated against a comprehensive regression suite before deployment. Existing behaviour is protected. Changes that break existing functionality are rejected before they reach any environment.
Manual Testing
Automated testing cannot replace human judgement. Manual exploratory testing evaluates edge cases, user experience quality, and behaviours that are difficult to specify in automated tests.
Release Management
Releases are planned, documented, and deployed using automated pipelines that enforce quality gates at every stage. Rollback procedures are defined and tested before any release reaches production.
Continuous Improvement
Quality metrics are tracked over time. Test coverage, defect rates, incident frequency, and time-to-resolution inform a continuous improvement programme that raises the quality bar with every release cycle.
Operational Transparency
Institutions deserve visibility into the systems they depend on.
Transparency is not just a value — it is an operational commitment. Institutions that depend on SUPENTIS platforms will have access to real-time status information, incident history, and scheduled maintenance windows through a dedicated operational transparency dashboard.
Incident History
Complete history of platform incidents, including root cause analysis and resolution timelines.
Coming SoonMaintenance Windows
Advance notice of scheduled maintenance, with expected impact and duration clearly communicated.
Coming SoonSecurity Advisories
Security advisories issued to institutional administrators when relevant vulnerabilities are identified or addressed.
Coming SoonRelease Notes
Detailed release notes published with every platform update, including security changes and new capabilities.
Coming SoonShared Responsibility
Security is a shared model. Transparency serves everyone.
Understanding what SUPENTIS protects and what remains the institution's responsibility enables effective security posture for both parties. Clarity here prevents gaps — and gaps are where incidents occur.
SUPENTIS Responsibility
What we protect.
Platform security architecture and secure defaults
Encryption of data in transit and at rest
Infrastructure security and patch management
AI governance and responsible AI controls
Availability and disaster recovery of the platform
Security of the platform codebase and dependencies
Audit logging infrastructure and tamper resistance
Security monitoring and threat detection at the platform level
Institution Responsibility
What you manage.
Administrative account management and credential hygiene
Role assignment and access provisioning for institution staff
Device security for devices used to access the platform
Governance of integration credentials and API keys
Training staff on security practices and awareness
Reporting suspected security incidents promptly
Managing exported data in customer-controlled environments
Institutional governance policies for platform usage
Security Research
Security as an active discipline.
Security is not a state that is achieved and maintained passively. It requires active research, continuous testing, and a culture that treats vulnerability discovery as valuable — regardless of its source.
Penetration Testing
SUPENTIS platforms undergo regular penetration testing by qualified security professionals. Testing covers network, application, and infrastructure attack surfaces. Results drive remediation actions tracked to closure.
Vulnerability Disclosure
SUPENTIS maintains a responsible disclosure programme. Security researchers who identify vulnerabilities in our platforms are invited to report them through a defined channel. All reports are acknowledged, investigated, and resolved in accordance with our disclosure policy.
Threat Modelling
Security threats are modelled during the design phase of every significant platform capability. Threat models are reviewed by security engineers and inform the security controls built into the implementation.
Security Publications
Security research findings that can be shared without creating risk are published through the SUPENTIS Research Centre — contributing to the wider security knowledge of the enterprise technology community.
Bug Bounty Programme
A formal bug bounty programme is planned for future launch. When established, it will invite the security research community to assist in the ongoing identification of vulnerabilities across the SUPENTIS platform ecosystem.
Responsible Disclosure
Found a security vulnerability?
We take all security reports seriously. Please do not disclose vulnerabilities publicly before giving us the opportunity to investigate and resolve them. Contact the security team directly.
Report a VulnerabilityFrequently Asked Questions
Answers to the questions institutions ask most.
Contact the Trust Team
The right team. The right conversation.
Trust enquiries deserve dedicated attention — not a general support queue. Each of the channels below connects directly to the team responsible for the subject you are raising.
Security Questions
Questions about platform security architecture, controls, or security posture.
security@supentis.com →Privacy Requests
Data subject access requests, deletion requests, or privacy enquiries under applicable regulations.
privacy@supentis.com →Compliance Enquiries
Questions about regulatory compliance, governance documentation, or certification status.
compliance@supentis.com →Responsible Disclosure
Reporting a security vulnerability or potential issue in any SUPENTIS platform or service.
security@supentis.com →Accessibility Feedback
Reporting an accessibility barrier or requesting assistance with accessing SUPENTIS platforms.
accessibility@supentis.com →Trust Partnerships
Research collaboration, institutional trust assessments, or joint governance initiatives.
Contact Us →All Trust Centre enquiries are acknowledged within one business day. Security and privacy matters are treated with urgency. The Trust team operates independently of the commercial organisation.

