Has Espo undergone a security audit or verification? Do you have a documented security strategy to enforce safe development? OWASP ASVS or something like it? I've seen the security policy on GitHub, looking for something a bit more thorough. Something to present to management to say "see, this is a secure and responsible project".