Security and resilience
How client systems are hosted, protected, monitored, backed up and recovered. This page describes the controls Opsenium applies as standard. Solutions can be designed to align with client security and governance requirements.
UK cloud hosting
Opsenium-managed systems are hosted on Microsoft Azure, in the UK South region by default. Each system has its own resource group, its own managed identities and its own key vault, so clients are separated at the platform level rather than by convention.
Access control and least privilege
Access to systems is role-based and scoped, enforced in the application at every relevant call site. Staff and administrators sign in through the client’s identity provider, such as Microsoft Entra ID, where one exists. Multi-factor authentication and single sign-on can be required for administrative access. Service identities are granted only the permissions they need.
Encryption and credentials
Data is encrypted in transit with TLS and at rest by the platform. Non-recoverable credentials issued by a system, such as passwords, PINs and device tokens, are stored using one-way hashing. Recoverable provider credentials and integration secrets are held in Azure Key Vault or encrypted at rest in the application with a versioned scheme, and are accessed through managed identities rather than shared keys.
Logging and audit
Systems record an audit trail of significant actions with the actor, the time and, where relevant, the before-and-after state, including drafts produced with AI assistance alongside the versions a person approved. Application telemetry and logs are retained in Azure Monitor for an agreed period. Audit records are available to the client.
Monitoring and alerting
Availability tests, application telemetry and alert rules are configured for every managed system. Alerts route to Opsenium and, where the client wants them, to the client. Background jobs record their attempts so that failures are visible rather than silent.
Backups
Databases use the platform’s point-in-time restore. Managed systems additionally take scheduled, encrypted backups to an independent provider under an immutable retention lock, so that a compromised environment cannot delete its own recovery position. Backup integrity is checked when the backup is written.
Business continuity and disaster recovery
Each managed system has documented recovery point and recovery time objectives, a runbook listing its resources including those managed by hand, and a documented rollback and recovery path appropriate to each application component and database change. Restores are rehearsed and the drill is dated and timed in the runbook.
Secure development
Code is version controlled, reviewed and tested automatically before deployment. Deployment pipelines authenticate to Azure with short-lived federated credentials rather than stored secrets. Infrastructure is defined as code. Security headers, rate limiting and restricted origins are standard on every service.
Dependency and patch management
Runtime and library dependencies are updated on a schedule under the managed service, and container images are rebuilt from current base images. Vulnerability advisories for the stack are monitored and urgent patches are applied outside the schedule.
Incident response
Incidents are tracked from report to resolution under the service agreement, with severity-based response targets. Significant incidents receive a written account covering cause, impact, resolution and the change made to prevent recurrence. Personal data breaches are handled in line with UK GDPR obligations and the client’s own procedures.
Data retention
Retention periods are agreed per system and per kind of data, and enforced by scheduled processes rather than by policy alone. Storage lifecycle rules are used for large or time-limited data such as media archives.
Exit and data portability
On payment, the client owns the delivered system, its source code, its infrastructure definitions and its data. Data can be exported in standard formats on request. On exit, under the notice and handover terms of the agreement, Opsenium hands over the repository, the runbook and the Azure resources to the client or another provider.
These controls are in production
The Bishops Emporium platform provides a working example: UK South hosting, scoped role-based access, one-way hashed credentials, encrypted secrets, managed identities, an audit trail with before-and-after snapshots, hourly encrypted off-site backups under an immutability lock, and a restore drill that is dated and timed in the runbook.
Security and operational controls in the case studyNeed a security summary for a procurement exercise?
We answer security questionnaires directly and can provide a written information security summary for a specific engagement.
Supplier information
Company, insurance and contracting details for procurement teams.
View supplier information