MAESTRO Trust Center

Accounting data belongs to the customer. Access does not.

MAESTRO uses layered, server-enforced controls to protect accounting, banking, tax and operational information. Security decisions are based on authenticated identity and explicit organisation membership—not on a hidden menu or a company ID supplied by a browser.

Continuous security controls and isolation monitoring active
Organisation isolation

Fail closed

Tenant and company selections are checked against active access records before enterprise API operations execute. Forged or unauthorised selectors are denied.

Identity and permissions

Least privilege

Named accounts, organisation memberships and role permissions limit each user to authorised business functions. Interface visibility never replaces server-side authorisation.

Encryption in transit

TLS 1.2 and 1.3

MAESTRO requires modern HTTPS transport, Secure and HttpOnly session cookies, HSTS and protections against clickjacking, MIME confusion and unsafe referrer disclosure.

Monitoring

Isolation is tested

Automated negative tests verify that foreign organisation and company identifiers are rejected. Authentication, permission and high-risk finance activity is designed to be auditable.

Application security

Defence in depth

Rate-limited authentication, CSRF protection, restricted browser origins, host validation, private configuration storage and dependency security reviews reduce the attack surface.

Data lifecycle

Controlled access

Backups and operational files are kept outside the public web root with restricted filesystem permissions. Data export and retention controls are part of the security programme.

Honest security, not an absolute promise

No responsible provider can claim that a complex system is impossible to attack. MAESTRO’s commitment is measurable controls, continuous verification, rapid remediation, transparent contractual responsibilities and independent assurance as the programme matures.

Security principles

For a security questionnaire, data-processing agreement or technical architecture review, contact your MAESTRO account representative. MAESTRO does not claim ISO, SOC or other independent certification until the relevant audit has been completed.