> For the complete documentation index, see [llms.txt](https://docs.tricloudnexus.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.tricloudnexus.io/platform-architecture/security-architecture.md).

# Security Architecture

An in-depth overview of the security measures embedded in the platform.

* Identity & Access (roles, tenants, least-privilege)
* Network & Segmentation (site, DMZ, cloud boundaries)
* Data Security (at rest, in transit, secrets)
* Compliance considerations (e.g., audit, traceability)

<figure><img src="https://570593659-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYMGRODsc2QD3N3wmfwTl%2Fuploads%2F1d5n5f5OsK2zLpKpg8uH%2Fimage.png?alt=media&amp;token=ab8b267b-3a3b-4b68-b2e7-bb440d42dced" alt=""><figcaption></figcaption></figure>

* Secure Device Attestation (X509 certificates)
* No inbound ports open
* No exposure to public Internet
* No public IP
* Segmented Network Support

Transparent gateway:

* Application deployment
* 2-way communication
* Remote management
* Private Docker repository
