Security Controls and Auditability
Bansoft combines configurable application safeguards with managed hosting controls to support identity protection, transaction security, operational oversight, and auditability.
What security controls are documented?
Bansoft includes configurable application-level safeguards for administrators, staff, users, transactions, sessions, and system access.
Identity and access
- Configurable password policies
- Authenticator-app, email, or SMS-based multi-factor options
- Device authentication and login-attempt controls
- Administrator IP restrictions and role-based permissions
Transaction and profile protection
- One-time-password options for transactions
- Profile-change and password-reset verification
- Security-key confirmation for selected operations
- Pending-request and approval workflows
System-wide safeguards
- IP allowlisting, blocklisting, and rate limiting
- Concurrent-session controls and inactivity timeouts
- Permission-violation blocking
- Emergency access suspension options
Logs, records, and controlled access
System logs and audit trails can record user and administrator activity, profile and account changes, transactions, security events, and API activity. Document access can be controlled through administrator classes and user groups.
Logging supports accountability and investigation, but retention, review procedures, and institutional control ownership remain part of the client governance framework.
Encryption and secure transport
Documented deployments use HTTPS with modern TLS, password hashing, protected sessions, and encryption for selected sensitive data and backups. Exact encryption design, key management, and hosting controls depend on the agreed environment.
Infrastructure protection by deployment scope
Managed hosting profiles can combine edge, server, network, and application controls.
Edge and traffic controls
Documented hosting profiles can use web-application firewall rules, DDoS mitigation, bot controls, rate limiting, and trusted-traffic rules before requests reach the origin environment.
Server and network controls
Origin protection can include server-side web-application firewall rules, restricted database access, network segmentation, and controlled administrative access.
Managed operations
Monitoring, patching, backups, maintenance, and security updates are handled within the agreed managed-service scope.
Controls support compliance; they do not replace it
Bansoft is designed to support security, auditability, document handling, and regulated-institution review. It does not by itself make an institution compliant, obtain regulatory approval, or remove the institution's responsibility for policies, risk decisions, monitoring, and regulatory obligations.
What should be confirmed?
- Required authentication methods
- Access and approval roles
- Logging and retention expectations
- Hosting and network controls
- Third-party security dependencies
Related Bansoft resources
Continue with the most relevant product, service, and evaluation information.