Your first Spark is on us.

Send your First Spark
Send your First Spark free
Ferrite

Security and Trust

Enterprise control begins with a clear boundary.

We deliver applications you own into infrastructure you control. Your identity, your credentials, your business data, your production approvals, and how the system is used under regulation all stay under your authority. Beneath the application, our closed-source Frame, Core, connectors, deployment, and integration technology runs under an embedded-use license.

This page walks through who owns each component, where the system runs, how we prepare releases, what evidence the application can produce, and how our access to your environment is governed.

Shared responsibility

Who controls the Ferrite application environment?

You control the production environment, and we build and support the application inside the authority you grant us. The contract and the Application Blueprint, which is the written record of the agreed application and where its boundary sits, together define the system boundary, the operating roles, the evidence, the access, release approval, and how a transition is handled.

Responsibility for each system area, split between the customer and Ferrite.
System areaCustomer responsibilityFerrite responsibility
Customer-specific applicationOwns the application and approves its production useDesigns, builds, tests, documents, and supports the agreed application
Production environmentControls cloud accounts, networking, policies, and production authorityProvides deployment requirements and performs agreed operations through approved access
Business dataOwns the data, classification, retention, and permitted useImplements agreed handling, validation, logging, and protection in the application boundary
Identity and credentialsControls identity authority, user approval, secrets, and privileged accessImplements the agreed identity, role, and service-integration patterns
Frame, Core, Fabric, connectors, deployment, and integration technologyReceives an embedded-use license for deployed versions while a Ferrite application remains in operationOwns the platform IP, source, releases, compatibility work, and license terms
ReleasesDefines approval authority and accepts production deploymentBuilds, tests, reviews, signs, documents, and submits releases for approval
Evidence and logsDefines destinations, retention, review, and presentationProduces the agreed application events, manifests, test records, and control outputs
Operational accessGrants, monitors, limits, and revokes accessUses approved access only for contracted delivery, Care, or incident work

Scroll the table sideways on a narrow screen

The foundation

The control foundation

01

Customer-controlled identity

The application plugs into your identity provider, your MFA, your user lifecycle, your role model, and your privileged-access rules. You remain the identity authority throughout.

02

Credentials stay inside the customer boundary

Production credentials and secrets stay in the stores you have approved. Ferrite never collects production passwords or secrets through public forms, email, chat, or the First Spark Assessment.

03

Core governs external communication

Every connection the application makes to the outside world passes through Core and the licensed integration layer. Core is where credentials, authorization, connector behavior, data movement, compatibility, logging, and evidence are all handled together. Adding an integration, or moving to a later connector, API, protocol, or compatibility release, comes through an approved Spark or your Ferrite Care coverage.

04

Releases remain reviewable

Any release can be traced from the original Spark through its review, tests, security results, documentation, signature, your acceptance, deployment, and rollback details. Production approval stays with you.

05

Evidence moves into customer systems

The application can send structured events and evidence into the logging, SIEM, GRC, ticketing, retention, and monitoring systems you have approved. You decide how that evidence is reviewed, retained, and presented.

06

Recovery is agreed before production

The Blueprint settles backup responsibilities, recovery procedures, target recovery objectives, availability expectations, incident roles, and your continuity requirements before anything goes live.

The customer-controlled environment, the licensed Ferrite platform beneath the application, and the governed paths in and outYOUR ENVIRONMENTCUSTOMER-OWNED APPLICATIONLICENSED FERRITE PLATFORM IPFRAMECONNECTORSCOREBUSINESS DATAIDENTITYCREDENTIALSLOGS AND EVIDENCEAPPROVAL AUTHORITYFERRITE ACCESSAPPROVED, LOGGEDREVOCABLEEXTERNAL SYSTEMS, REACHED THROUGH CORE

Operational access

How does Ferrite access the environment?

When we need to reach your environment, we do it the way you have approved and only within the scope set in the contract. The Blueprint spells out named or role-based access, least privilege, the authentication we have to meet, approval, logging, review, how emergency access works, and how you revoke it.

Continuity

What happens when Ferrite Care ends?

The application you own keeps running. The embedded-use license for the deployed Frame, Core, connectors, and integration components stays active for as long as you operate at least one Ferrite application.

What ends, on the terms in the contract, is the Care service around it: the monitoring, the Smith attention, the monthly Spark that comes included, and the future releases it covers. Later Core, connector, security, API, protocol, and compatibility releases come back through Care or an approved Spark. The Ferrite platform source code stays proprietary and is not provided or viewable.

Current position

Assurance and regulatory status

We would rather state our position plainly, including the parts that are not finished yet. Each item below carries the status it genuinely holds today.

Status: Available

Regulation-ready application engineering

The platform gives you a control foundation for identity, access, release handling, evidence output, and integration boundaries, together with application documentation and interfaces that connect into your logging, monitoring, and governance systems. The mapping to a specific regulation is worked out with you during the Blueprint.

Status: In progress

Ferrite organizational assurance

We hold no independent report today, and we will not imply otherwise. As independent reports are completed, we publish our assurance status right here.

Status: Customer authority

Customer compliance

You keep regulatory interpretation, policy, control operation, risk acceptance, and the final compliance determination. We supply the engineering support for that work within the agreed scope. The architecture on its own does not make you compliant.

Status: Planned

HIPAA-regulated workload enablement

The reference architecture, the contractual position, the operational controls, the vendor responsibilities, and the BAA approach are still being worked through.

Resource library

Trust resources

Every item carries its real status, and nothing here is offered for download before it has been written, reviewed, and approved for release.

Available
Published and open to read
Request access
Prepared for review on request
In progress
Being written now
Planned
Scheduled, not started
  • Request access

    Security architecture overview

    Walked through with your security team during the Blueprint. A written overview is being prepared for general release.

    Request access
  • Request access

    Shared-responsibility matrix

    The published table on this page is the current summary. The engagement-specific version is prepared with the contract.

    Request access
  • Request access

    Secure delivery and release overview

    Describes how a Spark becomes a reviewed, signed, documented release submitted for customer approval.

    Request access
  • Request access

    Data-flow and integration-boundary diagram

    Produced for the specific application during the Blueprint. A generic reference version is being drafted.

    Request access
  • In progress

    Vulnerability-reporting contact and process

    The reporting address, intake handling, and response commitments are being defined before publication.

  • In progress

    Service-provider and subprocessor list, when applicable

    The list is being compiled so it can be kept accurate and dated once published.

  • In progress

    Privacy and data-handling summary

    A plain-language summary is being written to sit alongside the published privacy policy.

  • Planned

    Business-continuity and incident-coordination summary

    Continuity and incident roles are agreed per engagement in the Blueprint. A general summary is scheduled.

  • Planned

    Current assurance reports or approved summaries

    No independent report exists today. Anything completed will be listed here with its date and scope.

Bring your security team into the Blueprint early.

We can map the application boundary, the platform license, the integrations, access, control responsibilities, evidence, and the assurance requirements with you before the build begins.