Security
Semsto is a business solution developed and offered by Aarvi Technology. Security is considered across the solution, implementation, hosting environment, user access, data handling, integrations, and ongoing support.
The security approach for each implementation may vary depending on the agreed solution scope and hosting model, including infrastructure managed for Semsto or infrastructure provided and managed by the client.
Jump to Section
- Introduction
- Information Security
- Hosting & Infrastructure
- Application & System Security
- Vulnerability Management
- Backup & Data Recovery
- Business Continuity
- Data Retention & Deletion
- Employee & Internal Security
- Security Incident Response
- Third-Party & Vendor Security
- Compliance & Requirements
- Review & Improvement
- Responsibilities by Hosting Model
- Security Requirements
- Security Disclaimer
Introduction
Purpose and Scope
This security framework describes the practices followed to help protect Semsto, customer information, systems, infrastructure, integrations, and related resources.
Security controls may be aligned with the customer's implementation model, infrastructure requirements, business processes, and applicable security policies.
Security Responsibilities
Aarvi Technology follows defined security practices for the components and infrastructure under its management.
Where Semsto is implemented on client infrastructure, security responsibilities may be shared between Aarvi Technology and the client according to the agreed implementation and support scope.
Employees, contractors, authorized users, and relevant third parties are expected to follow applicable security policies and access requirements.
Information Security
Data Classification
Information can be classified based on its sensitivity, business importance, and access requirements.
Appropriate handling and access controls can be applied to confidential, sensitive, internal, and general business information.
Role-Based Access Control
Semsto supports access management based on user roles, responsibilities, and business requirements.
Organizations can control which users can access specific capabilities, information, and operational functions.
Authentication and User Access
User access can be controlled through authorized accounts, permissions, password policies, and applicable authentication mechanisms.
Access requirements may also be aligned with the client's internal IT and security policies.
Data Encryption
Appropriate encryption practices can be used to help protect sensitive information during transmission and, where applicable, while stored.
The specific security configuration may depend on the selected hosting and infrastructure environment.
Client Data Protection
Customer data is treated as business-sensitive information.
Access to customer information is restricted according to authorized responsibilities, operational requirements, and the agreed implementation model.
Additional safeguards can be applied depending on the client's security, compliance, or infrastructure requirements.
Data Privacy
Customer data is handled according to applicable privacy requirements and agreed usage.
Aarvi Technology does not use customer information outside the purposes required to provide, operate, support, and maintain the agreed Semsto solution.
For more information, refer to the Privacy Policy.
Hosting and Infrastructure Security
Flexible Hosting Model
Semsto can be deployed using different hosting approaches depending on customer requirements.
The solution may be hosted on:
- Infrastructure managed for Semsto
- Cloud infrastructure selected for the implementation
- Client-owned or client-managed infrastructure
- Other agreed infrastructure environments
The hosting approach is finalized based on factors such as security, compliance, performance, infrastructure strategy, data location requirements, and operational needs.
Semsto-Managed Infrastructure
Where the infrastructure is managed as part of the Semsto solution, Aarvi Technology applies operational controls related to access, backups, monitoring, system maintenance, and infrastructure security.
Access to production systems is limited to authorized personnel based on operational requirements.
Client-Managed Infrastructure
Where Semsto is deployed on the client's own infrastructure, the client's IT environment, network controls, server policies, monitoring, backup strategy, and security standards may form part of the overall security model.
Aarvi Technology can work with the client's technical team to align the Semsto implementation with agreed infrastructure and security requirements.
Database Access
Database access should be limited to authorized personnel who require access for implementation, maintenance, troubleshooting, or support.
Access controls depend on the agreed hosting and infrastructure model.
Support Access
Where access to customer data or systems is required for support or troubleshooting, access should be provided only to authorized personnel and limited to the required scope.
For client-managed infrastructure, support access may be controlled according to the client's internal IT and security procedures.
Application and System Security
Secure Access
Semsto uses access controls and user permissions to help prevent unauthorized use of the solution.
Organizations can define access based on departments, responsibilities, and user roles.
Patch and Update Management
Software components, dependencies, servers, and related systems should be reviewed and updated as required to address known vulnerabilities and maintain system security.
Responsibility for infrastructure-level updates may depend on the agreed hosting model.
Network Security
Appropriate network security controls can include:
- Firewall rules
- Network access restrictions
- Secure communication protocols
- Server hardening
- Network segmentation
- Monitoring controls
The exact controls depend on the hosting environment and client requirements.
API and Integration Security
Where Semsto integrates with third-party systems, integration security is evaluated based on available APIs, authentication methods, data exchange requirements, and the security capabilities of the connected systems.
Access credentials and integration permissions should be limited to the required scope.
Vulnerability Management
Security testing is an important part of identifying and reducing technical risks.
Depending on the implementation and agreed scope, vulnerability management may include automated scanning, manual review, configuration assessment, penetration testing, and remediation activities.
Vulnerability Scanning
Automated tools may be used to identify known vulnerabilities across applications, systems, servers, or infrastructure.
Penetration Testing
Penetration testing may be carried out where required to evaluate the effectiveness of security controls and identify weaknesses that may be exploitable.
Security Review
Security reviews may include:
- Application security review
- Server and infrastructure configuration review
- Access-control review
- API security review
- Dependency and component review
- Network security review
Common Areas Reviewed
Security assessments may evaluate risks such as:
- Software vulnerabilities
- Misconfigurations
- Weak access controls
- Unpatched systems
- Insecure APIs
- Weak authentication
- Inadequate encryption
- Network exposure
- Operational security gaps
Vulnerability Management Process
The vulnerability-management process may include:
- Defining the scope
- Identifying vulnerabilities
- Analysing technical risk
- Prioritizing findings
- Documenting results
- Applying remediation
- Re-testing where required
Security testing is treated as an ongoing activity because technologies, infrastructure, and threats continue to evolve.
Backup and Data Recovery
Backup requirements are defined according to the hosting model, business requirements, and agreed solution scope.
For infrastructure managed for Semsto, backup practices are maintained as part of the operational environment.
Where Semsto is hosted on client infrastructure, backup responsibilities, schedules, retention, and recovery procedures may be aligned with the client's IT policies and agreed implementation responsibilities.
Business Continuity and Disaster Recovery
Business continuity and disaster-recovery planning help reduce disruption during unexpected technical or infrastructure events.
Where the infrastructure is managed for Semsto, recovery processes may include backups, infrastructure restoration, service recovery, and operational coordination.
For client-hosted implementations, disaster-recovery responsibilities and recovery targets depend on the client's infrastructure architecture and the agreed support scope.
Recovery objectives can be discussed and defined according to business-critical requirements.
Data Retention and Deletion
Data retention and deletion requirements may depend on the commercial agreement, hosting model, applicable policies, and customer requirements.
Where customer data is hosted on infrastructure managed for Semsto, retention and deletion can be handled according to the agreed policy and service terms.
Where Semsto is hosted on client infrastructure, the client generally retains control of its own infrastructure and stored data, subject to the agreed implementation responsibilities.
Customers can contact the Semsto solution team regarding specific data-retention or deletion requirements.
Employee and Internal Security
Security Awareness
Personnel involved in development, implementation, infrastructure, support, and operations are expected to follow applicable security procedures and access-control requirements.
Security awareness helps reduce risks related to unauthorized access, credential misuse, phishing, and data handling.
Access Based on Responsibility
Internal access should be granted according to job responsibilities and operational requirements.
Access should be reviewed and restricted when it is no longer required.
Incident Reporting
Security incidents or suspected security issues should be reported and reviewed through defined internal procedures.
Security Incident Response
Aarvi Technology follows a structured approach for handling security incidents affecting components under its management.
The response process may include:
- Identification
- Assessment
- Containment
- Investigation
- Remediation
- Recovery
- Review
For client-hosted environments, incident-response activities may be coordinated with the client's IT or security team depending on the source and scope of the incident.
Third-Party and Vendor Security
Semsto may use or integrate with third-party technologies, infrastructure providers, APIs, communication platforms, or other external services.
Relevant third-party services should be evaluated according to the requirements and risks of the implementation.
The security and availability of third-party platforms may also depend on the policies and controls maintained by those providers.
Compliance and Security Requirements
Security and compliance requirements differ between organizations and industries.
Semsto can be evaluated and configured according to relevant client requirements, infrastructure policies, operational controls, and applicable regulations.
Where specific security or compliance requirements exist, they should be discussed during solution evaluation and implementation so the appropriate architecture and responsibilities can be defined.
Security Review and Improvement
Security requirements change as technology, infrastructure, business processes, and threats evolve.
Security policies, infrastructure controls, application controls, access permissions, and operational practices should therefore be reviewed periodically and updated where required.
Security Responsibilities by Hosting Model
Managed for the solution
If Semsto Is Hosted on Infrastructure Managed for the Solution
Aarvi Technology may manage agreed areas such as:
- Infrastructure access
- Application deployment
- Backup operations
- Monitoring
- Server maintenance
- Application updates
- Security configuration
- Incident response for managed systems
Client infrastructure
If Semsto Is Hosted on Client Infrastructure
Responsibilities may be divided between Aarvi Technology and the client.
The client may manage areas such as:
- Physical or cloud infrastructure
- Network security
- Server administration
- Infrastructure monitoring
- Backup infrastructure
- Corporate security policies
- Identity and access infrastructure
Aarvi Technology may manage agreed areas related to:
- Semsto application deployment
- Application configuration
- Application updates
- Technical support
- Application-level troubleshooting
- Integration support
The exact responsibilities are defined according to the agreed implementation and support scope.
Have Specific Security Requirements?
Every organization has different security, infrastructure, hosting, and compliance requirements.
Talk to our team about your environment and we can discuss how Semsto can be implemented according to your organization's requirements.
Security Disclaimer
The information provided on this page describes the general security practices and controls that may be applied to Semsto implementations.
Security responsibilities, hosting arrangements, backup procedures, monitoring, access controls, recovery processes, integrations, and compliance requirements may vary depending on the client's infrastructure, agreed solution scope, deployment model, third-party services, and contractual responsibilities.
Where Semsto is hosted on client-managed infrastructure, the client is responsible for the security, availability, configuration, monitoring, backup, and protection of the infrastructure and systems under its control, unless otherwise agreed in writing.
Where infrastructure is managed as part of the Semsto solution, Aarvi Technology is responsible only for the security and operational controls specifically included within the agreed scope.
No system, application, network, or security control can guarantee complete protection against every possible threat, attack, vulnerability, or service disruption. Aarvi Technology applies reasonable security practices within the agreed scope but does not represent that Semsto will be completely free from security incidents or vulnerabilities.
Any specific security commitments, service levels, compliance obligations, recovery objectives, data-retention requirements, or responsibilities should be defined in the applicable proposal, statement of work, service agreement, or other written agreement between Aarvi Technology and the client.

