Available in the product
Organization roles, invitations, session controls, durable run history, and workspace-specific AWS workflow resources.
Five review layers
Durable run history records workflow steps, exceptions, review decisions, and connected-system writes. Security questionnaires and architecture review are handled during enterprise evaluation.
Organizations support owner, admin, and member roles with invitations and account session controls. SSO is not a default product feature; requirements are scoped before an enterprise rollout.
Workflow infrastructure is provisioned per workspace with workspace-specific stacks, function names, artifact storage, deployment roles, runtime roles, and scheduler roles.
Safivo uses managed provider connections, AWS Secrets Manager for runtime provider configuration, and short-lived assumed AWS role credentials. Browser and API traffic is served over HTTPS.
Connections and permissions are selected for the workflow. Retention, provider data flow, regional requirements, and deletion are documented for the deployment before production use.
Honest scope
Enterprise security is not one badge. It is a review of the actual workflow, providers, permissions, data path, and responsibilities.
Organization roles, invitations, session controls, durable run history, and workspace-specific AWS workflow resources.
Connected-system permissions, human review boundaries, write actions, retention requirements, and the workspace workflow region.
Data-processing terms, provider disclosure, security questionnaires, incident contacts, and any negotiated support commitments.
Safivo is not currently SOC 2 certified. SSO and universal data residency are not represented as default capabilities.