Security

Security belongs in the platform layer.

MERPH is designed around centralized identity, role-based permissions and controlled access across modules so security does not have to be reinvented independently for every operational function.

Identity

Centralized access

Users and roles are managed at the platform level so permissions can remain coherent across the customer environment.

Authorization

Role-based permissions

Capabilities and data visibility can be limited according to role, responsibility and implementation requirements.

Architecture

Least required exposure

Users should see the modules and functions required for their work rather than the entire enterprise stack by default.

Data

Controlled enterprise context

Connected data improves visibility, but access controls remain an explicit part of the relationship between users and records.

Integration

Deliberate connections

External systems should connect through defined interfaces and scoped access rather than ad hoc data duplication.

Deployment

Customer requirements matter

Production security architecture, hosting, audit controls and compliance requirements should be finalized for each deployment context.

Important

Security claims should match the deployed product.

This public site intentionally avoids unsupported compliance certifications or guarantees. Formal security claims should be added only after the implementation and evidence support them.

Document the production hosting model
Define authentication and MFA requirements
Document logging and audit behavior
Define backup, recovery and retention
Map any compliance obligations to actual controls