Security & Resilience
How Perspio keeps your data secure, isolated and available.
Security is built into how Perspio is designed, developed and run. This page summarises the controls that matter most to integrators and IT teams.
Certified to ISO/IEC 27001:2022
Inauro Pty Ltd, the company behind Perspio, is certified to ISO/IEC 27001:2022, the international standard for information security management. The certification covers the whole lifecycle of the Perspio SaaS platform, from design to deployment.
| Certificate ID | Certified by |
|---|---|
| ITGOV40403 | Intertek SAI Global |
Tenant isolation and data residency
- Multi-tenant by design. One platform serves every customer, and each tenant's data is isolated so that no other tenant can see or reach it.
- Your data stays in your region. Perspio runs two independent regions, AU and US, and a tenant's data stays in the region it's hosted in.
- Everyone on the latest version. Because every customer runs on the same platform, new features and fixes reach everyone as soon as they're released.
Access control
- Role-based access. Access profiles control which operations a user or API application can perform, and security groups control which assets it can see. See Roles and Security Groups.
- Short-lived tokens. Integrations authenticate with access tokens that last an hour, issued to an API application. See Authentication.
- Encrypted connections. All traffic to and from Perspio is encrypted with TLS.
Secure development
- Security from the start. Security is part of the development lifecycle from design onwards, not added before release.
- Continuous code analysis. Code is scanned automatically for vulnerabilities and quality issues with SonarCloud and Snyk.
- Real-time monitoring. Errors and platform health are tracked continuously.
- Independent testing. Third parties regularly penetration-test the platform.
Resilient cloud infrastructure
- Cloud-native. Perspio runs entirely on Microsoft Azure platform services, with no servers or legacy hardware of its own to maintain.
- Edge protection. A web application firewall and global entry points protect the platform from denial-of-service attacks and unauthorised access.
- Backups and recovery. Stored data is replicated to a secondary Azure region, and incoming data is also kept in its raw form in separate storage so it can be replayed. If a region has a major outage, the platform can be redeployed to its secondary region.
Transparency
Inauro takes part in the Cloud Security Alliance (CSA) STAR Registry. Its Consensus Assessments Initiative Questionnaire (CAIQ) sets out how Perspio meets cloud security best practice.
Last reviewedThis information was last reviewed in April 2026.
Updated 1 day ago
What’s Next
Did this page help you?

