Armure is designed for customer-controlled deployment inside your environment. See the architecture →
Armure Suiteby Simplified IT
Security posture

Security you can point to on a diagram.

Armure is built for buyers who must show their work to a regulator. The controls below are architectural, not bolted on — the perimeter is the product.

Customer-controlled residency

Deployment patterns are designed to keep data location and network boundaries under customer control.

No vendor call-home

Runtime operation does not require outbound vendor telemetry, licence validation or operational call-home traffic.

Shared standards-based identity

Armure Authentication Manager provides the common identity substrate, using supported standards and pluggable protocol handlers.

Encryption in transit

TLS across the DMZ; access protocols are brokered inward and never exposed at the edge.

Auditability

Pluggable audit logging and process/task history give you the evidence trail compliance teams ask for.

Least exposure

Keep DMZ responsibilities narrow and place stateful application and data services behind the internal boundary where the product topology supports it.

Standards

Implemented, not improvised

Armure speaks the protocols your security team already audits. That portability is itself a control — you are never trapped inside a proprietary scheme.

OAuth 2.0OATHSAMLBPMN 2.0WebDAVLDAPRDPSSHVNCTLSRESTSwagger
Responsible disclosure

Reporting a vulnerability

If you believe you have found a security issue in an Armure product, we want to hear from you. Email contact@simplifyit.in with a description and reproduction steps. Please give us reasonable time to remediate before any public disclosure.

What to include

Include the affected Armure product, version where known, deployment context, reproduction steps, potential impact and a minimal proof of concept. Do not include credentials, production personal data or unnecessary customer information.

Safe research

Please avoid destructive testing, denial-of-service activity, social engineering, persistence in customer environments or access to data that is not required to demonstrate the issue.

Coordinated disclosure

We will triage reports, coordinate remediation with the reporter where appropriate, and ask that public disclosure is deferred until customers have had reasonable opportunity to apply the fix or mitigation.

Need our security documentation?

We can share architecture detail, standards mappings and deployment guidance under NDA for evaluation.