M
Platform
Resources
Company

Pilot Program

A scoped build on your real numbers, before you commit.

Trust Center

Security, governance, and diligence, in one place.

URTM runs as a managed service on the systems you already own. Your data stays governed, access is enforced to your policy, and the Customer Portal runs on Microsoft Azure with security maintained for you.

Your Systems
ERP · CRM · Accounting · Spreadsheets

NYour systems stay your systems.

$

URTM intelligence layer
Governed access, business logic, reconciliation

NURTM governs the intelligence layer.

$

Portal · Dashboards · Eagle Eye
Dashboards, reporting and AI, by permission

NUsers see only what they're authorized to see.

Security Posture

Connect, don't copy.

URTM connects to the systems you already run, without creating an uncontrolled second copy of your data. The Customer Portal runs on Microsoft Azure, with governed access, tenant isolation, encryption in transit, and Row-Level Security down to the individual row.

No migration

Your systems stay your systems. Nothing is uploaded or replaced.

No new source of record

The portal connects to governed data sources, never becoming another operating system.

Access by row

Permissions are enforced to your policy, down to the individual row.

Managed service

Built on Microsoft Azure, configured and maintained by URTM.

Compliance

Built on certified infrastructure.

URTM connects to the systems you already run, without creating an uncontrolled second copy of your data. The Customer Portal runs on Microsoft Azure, with governed access, tenant isolation, encryption in transit, and Row-Level Security down to the individual row.

Microsoft

  • N
    Azure infrastructure
  • N
    Managed platform services
  • N
    Platform certifications (SOC, ISO)
  • N
    Physical & environmental controls

SHARED RESPONSIBILITY

URTM

  • N
    Application controls
  • N
    Tenant access model
  • N
    Row-Level Security configuration
  • N
    Data handling
  • N
    AI governance
  • N
    Operational monitoring

Inherited platform certifications:

SOC 1 / 2 / 3

ISO 27001 / 27018

GDPR / CCPA

+ regulated-workload offerings where applicable

Platform Controls

Configured. Maintained. Audited.

A defense-in-depth set of controls across Microsoft Azure, identity, application access, logging, and operations, configured to your governance policy and maintained as part of the managed service.

Secure sign-on

OIDC authorization-code flow with PKCE. No secrets in the browser.

Hardened tokens

Short-lived tokens with enforced state and nonce against replay.

Tenant isolation

Application-layer RBAC scopes each user to their tenant.

Row-level security

RLS on every model, so users see only the rows they may access.

Scoped embeds

Analytics delivered with expiring, identity-scoped embed tokens.

Encryption

TLS 1.2+ in transit. Azure-managed keys at rest.

Hardened web & API

Secure headers and cookies, legacy auth flows disabled.

Audit logging

Auth, access, config and admin actions logged, no customer data stored.

Compliance

Identity is the perimeter.

Access is layered, not a single gate. Each control above narrows what a user can reach, until only authorized rows remain.

Identity
Microsoft Entra ID + MFA + Conditional Access

Application
RBAC + tenant scoping

Analytics
Embed tokens + RLS

Data
Rows visible only when authorized

Data Handling

No new source of record.

URTM operates on governed data where it already lives instead of turning the Customer Portal into another system of record.

Connect

01

Secure, least-privilege access via DirectQuery and APIs.

$

Minimize

02

Only the processing analytics and reporting require.

$

Read-only

03

Source systems stay untouched and remain the record.

$

Protect

04

HTTPS-only endpoints with strict transport security and managed key handling.

Operations & Assurance

Monitored, tested, and maintained.

Because URTM runs the environment continuously, security controls stay current as systems, users, and requirements change.

Security monitoring

Azure Monitor, Application Insights and Microsoft Defender flag anomalies such as failed authentication and unusual access patterns.

Vulnerability management

Patching, scanning, remediation and risk-based prioritization, handled as part of the managed service.

Secure development

Code review, static and dynamic analysis, third-party component management and OWASP Top 10 mitigation.

Incident response

Documented detection, containment, remediation and client notification per contractual and regulatory obligations.

Cloud-only infrastructure

No physical data centers. Systems run in Microsoft Azure and inherit its physical and environmental protections.

Least-privilege operations

Production access is scoped to the work, granted when needed and revoked after use, with admin actions logged.

AI Governance

Same controls. Smarter answers.

Eagle Eye, URTM's operational AI agent, follows the same access, governance and traceability rules as every other surface. AI is not bolted on outside the security model.

Access-governed

Answers only from data the person asking is authorized to see.

N

Grounded

Every answer traces back to reconciled source data and the figures behind it.

Not training data

Customer data is not used to train foundation models.

Human oversight

AI assists the work; outputs stay reviewable, attributable and governed.

Security Package & Contact

Ready for diligence.

Everything your security, IT, and procurement teams typically ask for, ready to share. URTM can also complete questionnaires, support vendor review, or run a custom assessment for your requirements.

For security documentation, questionnaires, or vendor review, contact our security team at security@urtmsolutions.com

Included materials

  • Security fact sheet & architecture overview
  • Identity & token-handling design (OIDC + PKCE)
  • RBAC & tenant-isolation model
  • Row-Level Security approach
  • Embed-token approach
  • Data-handling & encryption model
  • Microsoft Azure compliance inheritance
  • AI governance overview

Security domains covered

  • N
    Data protection
  • N
    Access control
  • N
    Vulnerability management
  • N
    Audit logging
  • N
    Incident response
  • N
    Application security
  • N
    Business continuity
  • N
    Compliance monitoring
  • N
    Cloud infrastructure
  • N
    AI governance

Security FAQ

Quick answers for security teams.

Do you store our data?

No. The portal reads from your source systems through secure, least-privilege connections to deliver analytics; it isn't a new source of record.

How do users sign in?

OIDC authorization-code flow with PKCE on the Microsoft identity platform. Tokens are short-lived and exchanged server-side, with no secrets in the browser.

How is one tenant kept separate from another?

Application-layer RBAC, tenant scoping, workspace isolation, and identity-scoped access controls.

How is access controlled inside reports?

Role-based permissions, tenant scoping, scoped embed tokens, and Row-Level Security, so users see only the rows they're authorized to access.

Are you SOC 2 or ISO certified?

URTM runs on Microsoft Azure, which holds platform-level SOC and ISO certifications; URTM adds application-level controls under a shared-responsibility model.

How is our data encrypted?

TLS 1.2+ over HTTPS-only endpoints in transit; Azure-managed keys at rest.

What do you log?

Authentication, access, configuration and administrative events, plus operational telemetry. Customer data is not written to logs.

How is our data encrypted?

TLS 1.2+ over HTTPS-only endpoints in transit; Azure-managed keys at rest.