Security Overview

GSC Identity is the identity software division of Global Spectrum Consultants LLC
GSC Identity / Policies / Security Overview

Security Overview

An identity company has to be secure by design. Here is how we protect the GSC Identity platform and your data.

Last updated: October 11, 2026

1. Security principles

We build on least privilege, defense in depth, zero trust, and verifiable accountability. Every automated action in our products is policy-gated, explainable, and recorded.

2. Cloud infrastructure

GSC Identity services run on Microsoft Azure and inherit Azure’s physical, network, and environmental controls. We use Azure-native services for compute, data, secrets, and monitoring, and deploy infrastructure as code for consistent, reviewable changes.

Mission Control is hosted in Azure West US 2 (primary region) with failover to Azure Central US. All Mission Control customer data is stored in the United States.

3. Tenant isolation

All customer data is tagged with a tenant identifier and isolated through application-level enforcement across ingestion, processing, storage, and logging. Mission Control’s Sovereign plan offers a dedicated-tenant deployment option for stronger isolation, and IDENTA can be deployed fully air-gapped.

4. Encryption

  • Data in transit is encrypted with TLS 1.2 or higher.
  • Data at rest is encrypted using Azure platform encryption (AES-256).
  • Secrets and keys are stored in Azure Key Vault and rotated. No secrets are stored in code or repositories.
  • Mission Control uses Microsoft-managed encryption keys. Customer-managed keys (CMK) are on the roadmap.

5. Identity and access management

  • Customer sign-in uses Microsoft Entra ID single sign-on, with a documented email one-time-passcode fallback.
  • Service-to-service access uses managed identities rather than stored credentials.
  • Integrations request the minimum permissions needed, and customers approve them explicitly.
  • Internal access to production uses Microsoft Entra ID single sign-on with MFA enforced, and role-based access control on least privilege.

6. Governed AI

  • AI agents recommend; deterministic policies and human approval gates decide.
  • In Mission Control, every sensitive action waits for an authorized human approver before it executes.
  • Customer data is not used to train third-party models.

7. Audit logging

Security-relevant events and every agent recommendation, approval, and action are written to a hash-chained, tamper-evident audit log. Customers can export their audit trail. Platform telemetry flows to Azure Monitor and Log Analytics for monitoring and investigation.

8. Secure development

Our development practices include code review, automated testing, dependency and secret scanning, and separation of development, test, and production environments. Security requirements are considered at design time.

9. Monitoring and incident response

We monitor the platform continuously and alert on anomalies. Our incident response process covers detection, containment, eradication, recovery, and post-incident review. If we confirm a security incident affecting customer data, we notify affected customers without undue delay and in line with legal and contractual obligations.

10. Business continuity and data retention

We use automated backups, redundant Azure services, and documented recovery procedures, and we test restoration regularly. Mission Control applies the following retention periods:

  • Operational logs: 30 days
  • Identity telemetry: 90 days
  • Audit logs: 1 year
  • Backups: taken daily, retained for 14 days
  • Customer data deletion requests: processed within 30 days

11. Vendor management

Subprocessors are assessed for security before onboarding and bound by written data protection obligations.

12. Compliance

Our products help customers evidence controls in frameworks such as NIST, ISO 27001, SOC 2, and HIPAA. Mission Control does not claim certification itself, and use of our products does not by itself make a customer compliant. We align our own practices with recognized standards and will publish any attestations if and when they are obtained. Customers can request security documentation under NDA.

13. Report a vulnerability

We welcome responsible disclosure. Email info@globalspectrumconsultants.com with the subject “GSC Identity Security Report.” Please give us reasonable time to investigate before any public disclosure, and do not access data that isn’t yours or disrupt the service. We will not pursue legal action against good-faith researchers who follow these guidelines.