Azure-first, cloud-portable, API-driven. Start read-only, minimize permissions, and integrate only the data required for the agreed assurance scope.
Sliant's common API objects remain consistent across sectors. Sector packs change the obligations, deadlines, evidence expectations, and stress-test logic.
REST APIs and webhook events let Sliant integrate with existing systems without requiring a full system replacement.
Tenant → Sector Pack → Obligation → Owner → Deadline → Evidence → Finding → Remediation → Stress Test → Audit Package
POST /v1/evidenceGET /v1/obligationsPOST /v1/stress-testsPOST /v1/audit-packages
Read-only evidence access first. Write-back, workflow actions, or automated remediation require separately approved permissions and scope.
These are target architecture expectations for product design — not claims of certifications that have not yet been achieved.
Authorized admin sponsor, approved integration scope, identity configuration, data classification, network/API access, retention requirements, and security review contacts.
Tenant isolation design, least-privilege connectors, encryption, audit logging, secrets management, security documentation, data-flow diagrams, and integration test plans.
Hosting region, data residency, retention, SSO, service accounts, webhook allowlists, incident contacts, change windows, and production cutover.