> For the complete documentation index, see [llms.txt](https://docs.tricloudnexus.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.tricloudnexus.io/platform-architecture/security-architecture.md).

# Security Architecture

* Identity & Access (roles, tenants, least-privilege)
* Network & Segmentation (site, DMZ, cloud boundaries)
* Data Security (at rest, in transit, secrets)
* Compliance considerations (e.g., audit, traceability)

<figure><img src="/files/0soVnYx71SLYicek3FoT" alt=""><figcaption></figcaption></figure>

* Secure Device Attestation (X509 certificates)
* No inbound ports open
* No exposure to public Internet
* No public IP
* Segmented Network Support

Transparent gateway:

* Application deployment
* 2-way communication
* Remote management
* Private Docker repository
