Skip to main content

Security

This section covers the security layer of the DEUSS platform.

Sections

  • Identity Management Keycloak IDM, passkey authentication (WebAuthn), OIDC/OAuth2 flows, token strategy, frontend integration, and database migration.

  • Access Control Backend-owned permission model, protected resource registry, API boundary classification, service-to-service authentication, and authorization enforcement.

  • Cybersecurity Zero-trust architecture, backend-owned file lifecycle, security controls, data protection, and platform cybersecurity posture.

  • Regulatory Reporting ComplianceEvidence data mart, regulatory reporting pipeline, compliance schema, and reporting requirements.