LeaseSys reads some of the most sensitive records you own. Here is exactly how it treats them, with independently audited controls and complete observability.
Independently audited controls across security, availability, and confidentiality.
AES-256 at rest, TLS 1.3 in transit, with separate encryption for each tenant's keys.
Role-based access with fine-grained scopes, session controls, and break-glass workflows.
SSO, SAML, and SCIM with Azure AD, Okta, Google, and any SAML 2.0 provider.
Immutable, exportable, and queryable. Every action, agent decision, and access is recorded.
Continuous control monitoring with evidence collection and drift alerts.
Data classification, retention policies, redaction, and lifecycle controls.
Tenant isolation by design, with regional data-residency options.
LeaseSys reads from your systems and does not need write access to do its job. Every connection is scoped to what it needs, and you can disconnect it at any time.
Your portfolio data is never used to train models or shared with other customers. Every tenant is isolated. Retention, purge, and export are controlled by you.
We will walk through the security model in detail on the briefing.
Next: why we built it