Architecture

An assurance layer over the ecosystem you already operate.

Azure-first, cloud-portable, API-driven. Start read-only, minimize permissions, and integrate only the data required for the agreed assurance scope.

Integration model

Sliant's common API objects remain consistent across sectors. Sector packs change the obligations, deadlines, evidence expectations, and stress-test logic.

Your existing systems

Microsoft 365 / Graph / SharePointEntra IDServiceNow / JiraERP / HR / FinanceAWS / S3 / existing GRC / custom APIs
→

Sliant assurance layer

Requirements & sector packsOwners & deadlinesEvidence & findingsStress tests & remediationAudit packages & reporting
→

Outputs

Readiness dashboardsEscalationsEvidence packetsManagement reportsAPI/webhook events
API

What customers should expect

REST APIs and webhook events let Sliant integrate with existing systems without requiring a full system replacement.

Core objects

Tenant → Sector Pack → Obligation → Owner → Deadline → Evidence → Finding → Remediation → Stress Test → Audit Package

Typical API actions

POST /v1/evidence
GET /v1/obligations
POST /v1/stress-tests
POST /v1/audit-packages

Default principle

Read-only evidence access first. Write-back, workflow actions, or automated remediation require separately approved permissions and scope.

Security dependencies

Clear responsibilities before connection.

These are target architecture expectations for product design — not claims of certifications that have not yet been achieved.

Customer provides

Authorized admin sponsor, approved integration scope, identity configuration, data classification, network/API access, retention requirements, and security review contacts.

Sliant provides

Tenant isolation design, least-privilege connectors, encryption, audit logging, secrets management, security documentation, data-flow diagrams, and integration test plans.

Joint decisions

Hosting region, data residency, retention, SSO, service accounts, webhook allowlists, incident contacts, change windows, and production cutover.

Certification posture: Sliant should not claim SOC 2, ISO 27001, FedRAMP, StateRAMP, TX-RAMP, or other certification until the applicable assessment or authorization has actually been achieved.