Choose your deployment. Keep responsibility and access boundaries clear.
Permissions are part of the operating model, not an afterthought. Whether NEHANET runs hosted or on your own infrastructure, access is governed by company, role, region, and record scope from day one.
Hosted, or on your own infrastructure.
Hosted / Cloud
NEHANET-managed application hosting with browser-based access. No customer server installation is required — NEHANET and its infrastructure partners operate the application, and integration patterns are selected around your network boundaries.
On-Premises
Customer-operated infrastructure with NEHANET application installation. You provide a Windows server-class machine and Microsoft SQL Server; NEHANET installs Tomcat, Java, and the application. Remote installation and support access are governed by your policy.
Permissions are part of the operating model.
Four layers of control apply across every deployment, hosted or on-premises.
-
Identity and authentication
Account lifecycle, authentication method, session policy, single sign-on, and administrative controls.
-
Organization and role
Users are associated with company, role, region, business unit, team, and partner relationship.
-
Module, action, and record scope
Which applications a user can open, which operations they can perform, and which records they can see.
-
Review and audit
Provisioning, modification, suspension, periodic access review, logging, and evidence retention.
What a security review with NEHANET covers.
Current infrastructure, encryption, retention, backup, incident-response, subprocessor, and certification detail is provided through a security review scoped to your deployment — not published as a generic claim.
Architecture & tenancy
Hosting locations, logical isolation, network boundaries, application separation, and environments.
Encryption & key management
Transport and storage encryption, certificate ownership, key custody, and rotation.
Backups & recovery
Frequency, retention, location, restore testing, recovery point and time objectives.
Operations & incident response
Monitoring, vulnerability management, patching, logging, notification, and escalation.
Compliance & assurance
Current provider reports, certifications, penetration testing, and contract documentation.
Subprocessors & data lifecycle
Approved vendors, purpose, geography, retention, deletion, and termination handling.
What we confirm together before go-live.
Infrastructure
Customer-approved Windows server, SQL Server, storage, network, and environment prerequisites.
Application components
Supported Java, Tomcat, application, database, and browser versions, confirmed by engineering.
Remote access
Approved installation and support method, authorization, logging, time limits, and revocation.
SMTP relay, authentication, allowed senders, and alert behavior.
Backup and recovery
Customer backup, offsite retention, restore testing, and disaster-recovery ownership.
Patching and perimeter
Operating system, SQL, firewall, endpoint, and change-management responsibilities.
Deployment shouldn't be a burden on your IT team.
“Cloud deployment reduced the burden on our limited internal IT resources.”
Complete a deployment and security review before commercial scope is finalized.
The review produces a responsibility matrix, current requirements, a data-flow diagram, an access model, integration controls, a backup and recovery plan, and the trust documentation your team needs.