Security Policy
Security principles for Varajen’s multi-tenant workforce platform.
Security governance
Varajen maintains risk-based security policies, defined ownership, change controls, audit evidence, and periodic review appropriate to the service. Contractual schedules and customer questionnaires provide additional detail under confidentiality where needed.
Multi-tenant isolation
Application authorization binds requests to authenticated tenant and user context. Role-based boundaries separate platform administrators, tenant administrators, HR, recruiters, employees, vendors, and other portals. Sensitive operations use server-side authorization rather than UI visibility as the security boundary.
Identity and access
Varajen applies least privilege, session validation, role governance, credential protection, and administrative approval for privileged tenant lifecycle actions. Customers remain responsible for identity-provider security, role assignment, access reviews, and prompt offboarding.
Encryption and secrets
Supported production traffic uses encrypted transport. Managed cloud encryption protects stored production data where configured. OAuth tokens, signing material, and service credentials are kept outside source code in restricted secret stores.
Secure development and releases
Production changes use source controls, automated testing and security checks, controlled approvals, artifact integrity verification, and deployment evidence. Emergency procedures remain governed and auditable.
Infrastructure and resilience
Varajen uses cloud-native network controls, monitoring, backups and durability settings, workload identity, logging, web application protections, and recovery procedures appropriate to the deployed architecture. Exact commitments require a signed agreement.
Logging and monitoring
Security-relevant authentication, administrative, integration, deployment, and workflow events are logged as appropriate. Access to logs is restricted and retention follows contractual, operational, and legal requirements.
Incident response
Varajen triages suspected incidents, contains affected systems, investigates scope, restores service, preserves evidence, and communicates with affected customers as required by contract and law. Notification timing depends on confirmed impact and applicable obligations.
Vulnerability reporting
Report suspected vulnerabilities through /contact/request/?type=security. Include reproducible detail and avoid accessing unrelated tenant data, disrupting service, social engineering, destructive testing, or public disclosure before investigation. Never include live credentials or regulated data.
Shared responsibility
Customers must configure roles and integrations safely, protect endpoints and credentials, maintain lawful data handling, review audit activity, and train users. This page does not represent a certification unless a current independent certification is explicitly identified.
For vendor onboarding, security questionnaires, compliance review, data processing questions, or contract review, contact the Varajen team.