Banks hold Halden to the same standard as any critical ICT provider. Everything your security, outsourcing and DORA teams need is documented and published, not hidden behind a form.
OpenID Connect with Entra ID, Okta, Google and others; signatures checked against the provider’s keys. Roles from your groups, SCIM provisioning, password login can be switched off.
Admin, maker, checker and viewer roles per organisation, with a recorded periodic access review. No one approves their own rule.
TLS in transit, PBKDF2-hashed passwords and hashed tokens; data at rest encrypted at volume level.
Sign-ins, approvals, AI requests and exports, each chained to the last, so tampering breaks the chain. Export to your SIEM.
Independent tests [CADENCE]; summaries shared under NDA.
Nightly backup script, one-command restore, and a local mode that keeps working if the server is down.
We'll walk through your use case and show the product on data structured like yours.