Security & data protection

The controls production must prove.

ActLume's production requirements cover authenticated sessions, tenant isolation, server-side authorisation, managed encryption, audit records, backups, and sensitive-data redaction. Each control requires implementation and verification before customer use.

The required security baseline

Ordinary SaaS controls, verified before customer use.

Product policy keeps authorisation on the server and infrastructure protection managed. The browser boundary is a normal signed-in interface, not a key vault.

01

Identity and authorisation

Sessions must expire and support revocation. Access must follow roles and least privilege, with server-side enforcement on every action.

02

Tenant and data isolation

The organisation boundary must cover reads, writes, exports, background jobs, and audit records, with reciprocal isolation tests before customer use.

03

Managed protection

Production policy requires current approved TLS, managed encryption at rest and in backups, managed secrets, sensitive-detail redaction, and controlled recovery.

04

Audit and recovery

Access and workflow events must be attributable. Retention must be bounded, and backup and recovery behavior must be tested before customer use.

Data handling

How production must handle report data.

The production design stores report content in the service database and applies the control requirements above. Deployment evidence must establish the actual protection.

Exposure kept small

  • Credentials are prohibited from service storage and logs
  • Incident narrative is prohibited from telemetry
  • Organisation and role boundaries are mandatory
  • Retention and deletion rules require approval and evidence

The boundary stays explicit

The security record must identify each control, its operational scope, the responsible owner, relevant test evidence, and any exception that changes customer protection.

External portal

ActLume does not sign in to SRP for you.

The product design keeps portal credentials and the submission page under the authorised filer's control through a deliberate handoff.

  1. 1

    The case workspace design prepares reviewed values for handoff.

  2. 2

    Your filer opens the official portal in its own browser tab.

  3. 3

    The copy-assist boundary permits only one selected value per deliberate user gesture.

  4. 4

    Your filer signs in, pastes, reviews, submits, and confirms the result.

Read the integration boundary

For your security review

Evidence required for a security review.

Security reviews run on evidence, not slogans. These are the disclosures required before assurance or procurement review can rely on a control statement.

Data map

The data categories, purposes, system boundaries, regions, transfers, and retention that apply to the service.

Control evidence

Same-release evidence for the access, isolation, backup, and recovery controls described above.

Provider register

The processors in use, support access paths, incident contacts, and the approved change-notification process.

Next step

Compare plans built on this security baseline.

View pricing