# Security & Trust — Huntoso PAM-Pro > Built to Protect. Designed to Audit. How PAM-Pro handles your data, secures your keys, and maps to the compliance frameworks your auditors require. This page is for security teams evaluating PAM-Pro for enterprise deployment. **Live System Status:** [status.huntoso.ai](https://status.huntoso.ai) --- ## Architecture Overview PAM-Pro is built on a stateless, cloud-native foundation. All identity assertions are validated against your Microsoft Entra ID tenant in real time. ### Stateless by Design No traditional credential database. We store policy metadata only — never plaintext credentials. ### Key Management - All secrets stored in Azure Key Vault - Dual-keyed encryption (Microsoft-managed + customer-managed keys) - HSM-backed FIPS 140-2 Level 3 key storage available for regulated workloads ### Tenant Isolation Each customer environment is provisioned as a logically isolated tenant. No cross-tenant data access is architecturally possible. --- ## Data Handling ### What We Collect - Microsoft Entra ID object IDs and group membership (read-only sync) - Policy configurations and approval workflow state - Audit log entries (actor, action, timestamp, session ID) ### What We Do Not Collect - Passwords or credential material - Personal health information (PHI) - Financial account data ### Data Residency Data is stored in Azure regions matching your tenant's geography. Customers with data sovereignty requirements may specify an Azure region at provisioning. --- ## Compliance Mappings | Standard | Control | PAM-Pro Implementation | |---|---|---| | HIPAA | §164.312(a)(1) Access Control | JIT access with automatic revocation | | SOC2 CC6.1 | Logical Access | Least-privilege enforcement + MFA | | NIST 800-53 AC-6 | Least Privilege | Policy-enforced JIT with ticket IDs | | NIST 800-53 IA-2 | MFA | Platform-native Entra ID MFA on every action | | HITRUST CSF 01.0 | Access Control | Identity-based MFA attestation | --- ## Penetration Testing & Audits PAM-Pro undergoes annual third-party penetration testing. Summary reports are available to enterprise customers under NDA. --- ## Responsible Disclosure Report security vulnerabilities to: **security@huntoso.ai** --- ## Links - [Technical Architecture](https://huntoso.ai/technical-architecture.html) - [Audit & Compliance](https://huntoso.ai/audit-compliance.html) - [Platform Capabilities](https://huntoso.ai/capabilities.html) - [Documentation](https://huntoso.ai/pam-docs/what-is-pam.html)