Security & data handling

Trust is a set of specific controls.

What we collect, where the product runs, how firms are separated and which assurances we do—and do not—claim.

Public-source intelligenceSchema-per-tenant SaaSNo certification claimsPre-launch
Public plan evidenceCore intelligence derives from public DOL/EBSA Form 5500 disclosures and filed attachments.
Business contact dataAccess requests collect only the details needed to review and reply to an inquiry.
No participant feedsDo not send census, payroll, beneficiary, health or participant-account information through the public form.

How the service is separated.

5500RADAR runs on Microsoft Azure. The application is deployed as a containerized service, with PostgreSQL as the deployed database. Customer firms are separated by tenant-specific database schemas, and platform-operator access is distinct from firm-user access.

Transport
The public site and product are served over HTTPS. Security headers restrict framing, executable sources and browser capabilities on the marketing site.
Secrets
Deployed application secrets are supplied through Azure Key Vault rather than stored in the public website or committed source.
Tenant boundary
Each firm is resolved to its own tenant context before product data access. Shared public-reference data and platform administration data are classified separately.
Access
Firm access requires authentication. Platform-operator access uses a separate session and console. Sensitive administrative actions are recorded in an operator audit trail.
Development status
The service is pre-launch. There is currently no live customer data in the platform environment.

Claims we will not borrow.

5500RADAR does not currently claim SOC 1, SOC 2, ISO 27001 or similar certification. A cloud provider’s certifications are not presented as our own. If our assurance posture changes, this page and the changelog will identify what changed and when.

Security contact. Report a suspected vulnerability or data-handling issue to tkadura@5500radar.com. Do not include credentials, participant data or exploit details in the first email; we will arrange an appropriate channel.
Read the Privacy notice →