Skip to content
Demiton
Demiton
ISO 27001-aligned architecture

How Demiton handles your data

Credentials never rest on disk in plaintext. Operational data rests in Azure Australia East. Two things leave it during processing, and they are named on this page rather than hidden: model inference, and Exa web search.

Aligned means the certification is not done yet. The honest word for that is aligned.

Three things we can say out loud

Not a pledge. A description of where the data actually is.

Australian data residency

Operational data rests in Azure Australia East (Sydney). Two things leave it during processing, and both are named:

  • Model inference: Azure OpenAI
  • Web search: Exa

AES-256 at rest

Data at rest is encrypted with AES-256. In transit we enforce TLS 1.3.

  • Envelope encryption
  • Automated key rotation

Secrets out of the database

Integration secrets are never stored in the application database. They are isolated in hardware-backed Azure Key Vault.

  • Azure Key Vault integration
  • Just-in-time access
The handshake

Credentials never rest on disk

Most integration platforms write credentials to temporary disks while they work. If that server is compromised, those secrets are exposed.

Demiton keeps a credential in memory only, for the life of one handshake:

  1. Ingestion - The credential is pulled into an ephemeral RAM buffer.
  2. Use - It authenticates the call, and nothing more.
  3. Closure - The buffer is zeroed and the audit line is written.

Your registers do not live in RAM. They persist, encrypted at rest. It is the secrets that never do.

Source Systems
Business Central · Assignar · Employment Hero Payroll
↓
Civil Memory
Transform.Align.Encrypt()
Secrets in RAM only
ACTIVE
↓
Controlled Output
Reports · Dashboards · Audit Trail

Technical Controls

For the person who has to sign off on it.

For certifications, data residency, retention and audit posture, see Security & Compliance.

Control AreaImplementation
Application SecurityStatic analysis (Bandit SAST), secret scanning (trufflehog), and dynamic analysis (OWASP ZAP DAST).
Access Control (RBAC)Multi-factor authentication enforced. Role-based access tied to Microsoft Entra ID.
Network SecurityAzure Virtual Network, Private Link, and strict egress allow-listing for integration endpoints.
Audit LoggingImmutable logs of every transaction attempt, IP address, and outcome. Retained in cold storage.
Disaster RecoveryBackups in Azure Australia East.

Responsible Disclosure

If you find a vulnerability, tell us at support@demiton.io. We triage every report and respond.

Two processing exceptions leave Australia, and they are the only two: model inference on Azure OpenAI, and Exa web search. If you need the residency position in writing for a procurement team, ask for the whitepaper.

Common questions

Where does Demiton store my data?

Operational data rests in Microsoft Azure Australia East (Sydney). Two things leave it during processing: model inference runs on Azure OpenAI, and Exa web search leaves by design. Those are the only two, and they are named here rather than hidden in a footnote.

How does Demiton encrypt my data?

At rest, AES-256. In transit, TLS 1.3. Integration secrets sit in hardware-backed Azure Key Vault with automated key rotation.

Does Demiton store my integration credentials on disk?

No. Credentials are pulled from source systems into an ephemeral RAM buffer, used for the operation, and then zeroed out. They are never written to disk in plaintext.

What authentication does Demiton use?

Microsoft Entra ID (OIDC), with multi-factor authentication enforced. Every action traces to a named person and lands in an append-only audit trail.

How do I report a security vulnerability?

Email support@demiton.io. We triage every report and respond.