eGARC International

Security

Security & Trust

eGARC is designed to help organizations manage audit, risk, compliance, governance, and fraud information with appropriate security and access controls. This page provides an overview of our security approach and shared security responsibilities.

Security status

No publicly reported active security incident.

Security areas:CoreImportantCritical

Security is an important part of the eGARC platform. We design our application, infrastructure, authentication controls, and operational processes with the goal of protecting organizational information from unauthorized access, loss, misuse, and disruption. Security controls may evolve as the platform, infrastructure, and threat environment change.

eGARC uses authentication and session-management mechanisms to help protect user accounts and platform access. Organizations are responsible for maintaining strong credentials, assigning appropriate users, reviewing access regularly, and promptly disabling accounts that are no longer required. Additional authentication controls may be introduced or required for specific accounts, environments, or services.

Access to eGARC functionality and organizational information may be controlled through roles, permissions, modules, and other authorization mechanisms. These controls are intended to help ensure that users can access only the functionality and information appropriate to their responsibilities. Customers remain responsible for configuring and reviewing organizational permissions correctly.

eGARC is designed to support organizational environments where customer information is logically separated between tenants or organizational accounts. Application authorization and data-access controls are used to help prevent users from accessing information belonging to another organization. Tenant isolation is supported by application architecture, access controls, and backend authorization mechanisms.

eGARC uses security measures designed to protect information while it is transmitted between users and platform services. Where appropriate, sensitive information may also be protected through encryption or other security mechanisms while stored. The specific technologies and configurations used may vary by service, infrastructure component, and deployment environment.

The eGARC platform relies on application infrastructure, databases, networking components, hosting environments, and supporting services. We use reasonable technical and organizational measures intended to reduce infrastructure-related security risks. This may include restricted administrative access, environment separation, secure configuration practices, system updates, monitoring, and other operational controls.

eGARC may maintain application and security-related logs to support operational monitoring, troubleshooting, auditing, abuse prevention, and security investigations. Depending on the feature or service, logs may include authentication events, account activity, configuration changes, workflow actions, system events, and other relevant operational information. Access to security-sensitive logs is restricted according to applicable permissions and operational requirements.

Where applicable, eGARC uses backup and recovery procedures designed to support the restoration of platform information and services following technical failures or other disruptive events. Backup frequency, retention, recovery objectives, and restoration procedures may vary according to the service and infrastructure environment. Backups are not a substitute for customer-maintained copies of information where independent retention is required.

We monitor the security of the eGARC platform and may apply software updates, dependency upgrades, configuration changes, patches, and other corrective measures when appropriate. Security issues may be assessed according to their potential impact and urgency. Remediation timelines can vary depending on the nature of the issue, affected component, available mitigation, and operational circumstances.

If we identify a security incident that affects the eGARC platform or customer information, we will take reasonable steps to investigate, contain, mitigate, and recover from the incident. Where required by applicable law or contractual obligations, affected customers or relevant authorities may be notified. Incident response procedures may include investigation, access restriction, system remediation, monitoring, and post-incident review.

Security is a shared responsibility. Customers are responsible for protecting account credentials, managing user access, configuring roles and permissions appropriately, reviewing organizational activity, maintaining appropriate internal controls, and reporting suspected security incidents. Customers should also avoid uploading information that they are not authorized to process through the platform.

If you believe you have discovered a security vulnerability affecting eGARC, please report it responsibly through the designated eGARC security or support contact. Please provide enough information for our team to understand and reproduce the issue where possible. Security researchers should avoid accessing, modifying, deleting, or disclosing customer information and should not intentionally disrupt eGARC services while investigating a suspected vulnerability.

Security principles

Built around protection and accountability

Least-privilege access
Tenant-aware authorization
Secure authentication
Operational monitoring
Security-focused updates
Incident response procedures

Security is a shared responsibility

eGARC maintains platform-level security controls, while customers are responsible for protecting credentials, managing access, configuring permissions, and maintaining appropriate security practices within their organization.

Found a security issue?

Please report suspected vulnerabilities responsibly through the official eGARC security or support channel. Avoid accessing customer data, modifying information, or disrupting production services while investigating a suspected issue.