Trust Center
Security, governance, and diligence, in one place.
URTM runs as a managed service on the systems you already own. Your data stays governed, access is enforced to your policy, and the Customer Portal runs on Microsoft Azure with security maintained for you.
Your Systems
ERP · CRM · Accounting · Spreadsheets
Your systems stay your systems.
URTM intelligence layer
Governed access, business logic, reconciliation
URTM governs the intelligence layer.
Portal · Dashboards · Eagle Eye
Dashboards, reporting and AI, by permission
Users see only what they're authorized to see.
Security Posture
Connect, don't copy.
URTM connects to the systems you already run, without creating an uncontrolled second copy of your data. The Customer Portal runs on Microsoft Azure, with governed access, tenant isolation, encryption in transit, and Row-Level Security down to the individual row.
No migration
Your systems stay your systems. Nothing is uploaded or replaced.
No new source of record
The portal connects to governed data sources, never becoming another operating system.
Access by row
Permissions are enforced to your policy, down to the individual row.
Managed service
Built on Microsoft Azure, configured and maintained by URTM.
Compliance
Built on certified infrastructure.
URTM connects to the systems you already run, without creating an uncontrolled second copy of your data. The Customer Portal runs on Microsoft Azure, with governed access, tenant isolation, encryption in transit, and Row-Level Security down to the individual row.
Microsoft
- Azure infrastructure
- Managed platform services
- Platform certifications (SOC, ISO)
- Physical & environmental controls
SHARED RESPONSIBILITY
URTM
- Application controls
- Tenant access model
- Row-Level Security configuration
- Data handling
- AI governance
- Operational monitoring
Inherited platform certifications:
SOC 1 / 2 / 3
ISO 27001 / 27018
GDPR / CCPA
+ regulated-workload offerings where applicable
Platform Controls
Configured. Maintained. Audited.
A defense-in-depth set of controls across Microsoft Azure, identity, application access, logging, and operations, configured to your governance policy and maintained as part of the managed service.
Secure sign-on
OIDC authorization-code flow with PKCE. No secrets in the browser.
Hardened tokens
Short-lived tokens with enforced state and nonce against replay.
Tenant isolation
Application-layer RBAC scopes each user to their tenant.
Row-level security
RLS on every model, so users see only the rows they may access.
Scoped embeds
Analytics delivered with expiring, identity-scoped embed tokens.
Encryption
TLS 1.2+ in transit. Azure-managed keys at rest.
Hardened web & API
Secure headers and cookies, legacy auth flows disabled.
Audit logging
Auth, access, config and admin actions logged, no customer data stored.
Compliance
Identity is the perimeter.
Access is layered, not a single gate. Each control above narrows what a user can reach, until only authorized rows remain.
Identity
Microsoft Entra ID + MFA + Conditional Access
Application
RBAC + tenant scoping
Analytics
Embed tokens + RLS
Data
Rows visible only when authorized
Data Handling
No new source of record.
URTM operates on governed data where it already lives instead of turning the Customer Portal into another system of record.
Connect
01
Secure, least-privilege access via DirectQuery and APIs.
Minimize
02
Only the processing analytics and reporting require.
Read-only
03
Source systems stay untouched and remain the record.
Protect
04
HTTPS-only endpoints with strict transport security and managed key handling.
Operations & Assurance
Monitored, tested, and maintained.
Because URTM runs the environment continuously, security controls stay current as systems, users, and requirements change.
Security monitoring
Azure Monitor, Application Insights and Microsoft Defender flag anomalies such as failed authentication and unusual access patterns.
Vulnerability management
Patching, scanning, remediation and risk-based prioritization, handled as part of the managed service.
Secure development
Code review, static and dynamic analysis, third-party component management and OWASP Top 10 mitigation.
Incident response
Documented detection, containment, remediation and client notification per contractual and regulatory obligations.
Cloud-only infrastructure
No physical data centers. Systems run in Microsoft Azure and inherit its physical and environmental protections.
Least-privilege operations
Production access is scoped to the work, granted when needed and revoked after use, with admin actions logged.
AI Governance
Same controls. Smarter answers.
Eagle Eye, URTM's operational AI agent, follows the same access, governance and traceability rules as every other surface. AI is not bolted on outside the security model.
Access-governed
Answers only from data the person asking is authorized to see.
Grounded
Every answer traces back to reconciled source data and the figures behind it.
Not training data
Customer data is not used to train foundation models.
Human oversight
AI assists the work; outputs stay reviewable, attributable and governed.
Security Package & Contact
Ready for diligence.
Everything your security, IT, and procurement teams typically ask for, ready to share. URTM can also complete questionnaires, support vendor review, or run a custom assessment for your requirements.
For security documentation, questionnaires, or vendor review, contact our security team at security@urtmsolutions.com
Included materials
- Security fact sheet & architecture overview
- Identity & token-handling design (OIDC + PKCE)
- RBAC & tenant-isolation model
- Row-Level Security approach
- Embed-token approach
- Data-handling & encryption model
- Microsoft Azure compliance inheritance
- AI governance overview
Security domains covered
Security FAQ
Quick answers for security teams.
Do you store our data?
No. The portal reads from your source systems through secure, least-privilege connections to deliver analytics; it isn't a new source of record.
How do users sign in?
OIDC authorization-code flow with PKCE on the Microsoft identity platform. Tokens are short-lived and exchanged server-side, with no secrets in the browser.
How is one tenant kept separate from another?
Application-layer RBAC, tenant scoping, workspace isolation, and identity-scoped access controls.
How is access controlled inside reports?
Role-based permissions, tenant scoping, scoped embed tokens, and Row-Level Security, so users see only the rows they're authorized to access.
Are you SOC 2 or ISO certified?
URTM runs on Microsoft Azure, which holds platform-level SOC and ISO certifications; URTM adds application-level controls under a shared-responsibility model.
How is our data encrypted?
TLS 1.2+ over HTTPS-only endpoints in transit; Azure-managed keys at rest.
What do you log?
Authentication, access, configuration and administrative events, plus operational telemetry. Customer data is not written to logs.
How is our data encrypted?
TLS 1.2+ over HTTPS-only endpoints in transit; Azure-managed keys at rest.