Govern the website boundary
HTTPS, browser security controls, consent choices and public enquiry handling are treated as a distinct public-site boundary.
Twin7 Security & Trust
How Twin7 approaches public-site security, data boundaries, engineering governance, security reporting and deployment-specific assurance.
Public trust surface; deployment-specific controls remain governed.
ENGINEERING QUESTION
It can explain the controls and governance boundaries that are evidenced for the public website and the engineering approach. Customer authentication, hosting, data processing, resilience and certification claims remain dependent on the relevant deployment and separately evidenced status.
CONTROLLED PATHWAY
HTTPS, browser security controls, consent choices and public enquiry handling are treated as a distinct public-site boundary.
Engineering Intelligence recommendations support controlled review and are not presented as autonomous safety, compliance or operational authority.
Hosting, identity, data, monitoring, resilience and assurance controls depend on the agreed solution boundary.
EVIDENCE + BOUNDARIES
TRUST BOUNDARY
Public-site controls, Engineering Intelligence governance and deployment-specific assurance are intentionally distinguished.
The Twin7 public website is served over HTTPS with governed production configuration and browser security controls. Security controls for the Twin7 Engineering Intelligence Platform and for customer deployments are governed separately and depend on the agreed architecture, operating model and deployment boundary.
Public-website enquiries, consent choices and optional analytics are governed through the Twin7 Privacy Policy and Cookies information. This public trust page does not create broader claims about customer data processing, retention or hosting arrangements, which must be defined for the relevant service and engagement.
The public marketing website is not a specification for customer authentication or authorisation. Identity, access and administrative controls for a Twin7 platform or customer environment are determined by the relevant deployment architecture and requirements. Capabilities such as single sign-on, multi-factor authentication or role-based access should be confirmed for the specific solution rather than assumed from this website.
Twin7 is designed around governed engineering evidence, traceability, provenance and explainability. Engineering Intelligence recommendations are intended to support controlled engineering judgement and review; they are not presented by this website as autonomous authority for safety, compliance or operational decisions.
If you believe you have identified a security issue affecting the Twin7 public website or a Twin7 service, use the Twin7 Contact route and clearly identify the message as a security report so that it can be triaged appropriately. Do not include passwords, private keys or unnecessary sensitive data in an initial report.
Security, regulatory and assurance requirements are assessed against the scope of the relevant engagement and deployment. Twin7 and Geonation do not use this page to claim ISO 27001 certification, SOC 2 attestation, penetration-test certification or another independent security certification unless that status is separately evidenced and explicitly stated.
Twin7 can be engineered for different operating and deployment contexts. The applicable hosting, network, identity, data, monitoring, resilience and assurance controls therefore depend on the agreed solution boundary. This public website describes the trust approach; it is not a universal customer-environment security specification.
TWIN7 BY GEONATION