INFORMATION SECURITY
Information security must be part of the architecture.
Information moves between users, processes, documents, AI services and enterprise systems. At every stage it must be clear who may access it, in what context, under which rules and how actions can be audited afterwards.
ALTAIR builds information security into DMS/ECM, electronic records, process, integration and automation architecture from the start.
- Identity & Access
- Process Controls
- Integrity & Auditability
- Secure Integration
- Operational Resilience
SECURITY BY DESIGN
Security is not a separate layer added before go-live.
Security requirements shape identity and access, roles and responsibilities, logging, confidentiality, integrity, integrations, change control, recovery and long-term document trust. They belong in the information model, process design, integration architecture and operating model.
IDENTITY & ACCESS
The right information for the right person — in the right context.
Access depends on identity, role, responsibility, process and organisational context, information classification and process state. Central identity, SSO, MFA, groups, roles and fine-grained permissions may be used where appropriate. Users should receive only the information and operations required for their responsibility.
ACCOUNTABILITY & AUDITABILITY
Controlling access is not enough. It must also be demonstrable.
Meaningful audit links user identity, time and operation to the affected document, metadata change, process step, approval, decision, permission change or transfer to another system. It should provide process evidence, not merely a large volume of technical logs without context.
DOCUMENT INTEGRITY & TRUST
An electronic document must remain trustworthy over time.
Origin, change and version history, the valid version, author or approver, event timing, metadata, relationships and process context establish meaning. Electronic signatures, seals and timestamps belong in the document lifecycle. In relevant environments, eIDAS is a regulatory framework for electronic identification and trust services, not a certification claim.
SECURITY IN BUSINESS PROCESSES
Security rules must work inside the process.
Segregation of duties, multi-level approval, stage-based access, mandatory-field validation, decision audit, exception escalation and controlled closure, retention or disposal can be enforced through workflow. Automation can therefore implement security and control principles, not only efficiency.
SECURE INTEGRATION
Information must remain protected between systems.
Connections among DMS, ERP, business applications, portals, identity services, databases, office applications and AI platforms require system authentication, least-required data access, protected communication, permission mapping, error logging and failure handling. Protection covers transport and the meaning, scope and legitimacy of exchanged information.
AI & INFORMATION SECURITY
AI must not bypass the organisationʼs security model.
Enterprise Document AI must consider which documents it may access, user permissions, sensitive data, processing location, retention, tenant separation, auditability and human verification where required. AI belongs inside a governed information environment, not above unrestricted organisational data.
INFORMATION LIFECYCLE
Security changes with the information lifecycle.
Creation and receipt establish provenance, classification and initial access. Active processing controls workflow, changes, versions and responsibility. Sharing and integration control recipient and purpose. Record and retention preserve context, integrity, audit history and retention; archive or disposal follows relevant rules in a controlled way.
RESILIENCE & CONTINUITY
Security also includes the ability to continue operating.
Depending on the environment, protection may include backup and restore, high availability, monitoring, diagnostics, controlled configuration and updates, operational documentation, dependency and incident management, disaster recovery and continuity. The actual scope must reflect the information and processes supported.
CLOUD, ON-PREMISE & HYBRID
The security model must reflect the actual architecture.
On-premise, private or public cloud and hybrid environments divide responsibility differently. The decisive factor is not the label but clear ownership across identity, data, applications, infrastructure, operations and recovery among customer, infrastructure provider and application supplier.
STANDARDS & REGULATION
We translate regulation and standards into architectural requirements.
Depending on the project, ISO/IEC 27001 for information-security management systems, ISO/IEC 27017 for cloud security controls, ISO/IEC 27018 for personal data in public clouds, GDPR, eIDAS, or NIS2 and applicable national requirements may be relevant. These are standards or regulations, not a list of ALTAIR certifications; legal conformity depends on the actual solution and organisational scope.
SECURITY & INFORMATION GOVERNANCE
Protecting information means understanding its meaning.
Information differs in value, sensitivity, ownership, lifecycle and protection needs. Information Governance establishes what information exists, why it is needed, who is responsible, where it is used and how long it must remain available and trustworthy. Without that context, technology can be secured, but the right information is harder to protect appropriately.
