01
Customer-controlled identity
The application plugs into your identity provider, your MFA, your user lifecycle, your role model, and your privileged-access rules. You remain the identity authority throughout.
Your first Spark is on us. A free mockup of your software in about five minutes.
Send your First SparkSecurity and Trust
We deliver applications you own into infrastructure you control. Your identity, your credentials, your business data, your production approvals, and how the system is used under regulation all stay under your authority. Beneath the application, our closed-source Frame, Core, connectors, deployment, and integration technology runs under an embedded-use license.
This page walks through who owns each component, where the system runs, how we prepare releases, what evidence the application can produce, and how our access to your environment is governed.
The foundation
01
The application plugs into your identity provider, your MFA, your user lifecycle, your role model, and your privileged-access rules. You remain the identity authority throughout.
02
Production credentials and secrets stay in the stores you have approved. Ferrite never collects production passwords or secrets through public forms, email, chat, or the First Spark Assessment.
03
Every connection the application makes to the outside world passes through Core and the licensed integration layer. Core is where credentials, authorization, connector behavior, data movement, compatibility, logging, and evidence are all handled together. Adding an integration, or moving to a later connector, API, protocol, or compatibility release, comes through an approved Spark or your Ferrite Care coverage.
04
Any release can be traced from the original Spark through its review, tests, security results, documentation, signature, your acceptance, deployment, and rollback details. Production approval stays with you.
05
The application can send structured events and evidence into the logging, SIEM, GRC, ticketing, retention, and monitoring systems you have approved. You decide how that evidence is reviewed, retained, and presented.
06
The Blueprint settles backup responsibilities, recovery procedures, target recovery objectives, availability expectations, incident roles, and your continuity requirements before anything goes live.
Operational access
When we need to reach your environment, we do it the way you have approved and only within the scope set in the contract. The Blueprint spells out named or role-based access, least privilege, the authentication we have to meet, approval, logging, review, how emergency access works, and how you revoke it.
Continuity
The application you own keeps running. The embedded-use license for the deployed Frame, Core, connectors, and integration components stays active for as long as you operate at least one Ferrite application.
What ends, on the terms in the contract, is the Care service around it: the monitoring, the Smith attention, the monthly Spark that comes included, and the future releases it covers. Later Core, connector, security, API, protocol, and compatibility releases come back through Care or an approved Spark. The Ferrite platform source code stays proprietary and is not provided or viewable.
Current position
We would rather state our position plainly, including the parts that are not finished yet. Each item below carries the status it genuinely holds today.
Status: Available
The platform gives you a control foundation for identity, access, release handling, evidence output, and integration boundaries, together with application documentation and interfaces that connect into your logging, monitoring, and governance systems. The mapping to a specific regulation is worked out with you during the Blueprint.
Status: In progress
We hold no independent report today, and we will not imply otherwise. As independent reports are completed, we publish our assurance status right here.
Status: Customer authority
You keep regulatory interpretation, policy, control operation, risk acceptance, and the final compliance determination. We supply the engineering support for that work within the agreed scope. The architecture on its own does not make you compliant.
Status: Planned
The reference architecture, the contractual position, the operational controls, the vendor responsibilities, and the BAA approach are still being worked through.
Resource library
Every item carries its real status, and nothing here is offered for download before it has been written, reviewed, and approved for release.
Request access
Walked through with your security team during the Blueprint. A written overview is being prepared for general release.
Request accessRequest access
The published table on this page is the current summary. The engagement-specific version is prepared with the contract.
Request accessRequest access
Describes how a Spark becomes a reviewed, signed, documented release submitted for customer approval.
Request accessRequest access
Produced for the specific application during the Blueprint. A generic reference version is being drafted.
Request accessIn progress
The reporting address, intake handling, and response commitments are being defined before publication.
In progress
The list is being compiled so it can be kept accurate and dated once published.
In progress
A plain-language summary is being written to sit alongside the published privacy policy.
Planned
Continuity and incident roles are agreed per engagement in the Blueprint. A general summary is scheduled.
Planned
No independent report exists today. Anything completed will be listed here with its date and scope.
We can map the application boundary, the platform license, the integrations, access, control responsibilities, evidence, and the assurance requirements with you before the build begins.