Security & data protection

Know where incident data goes and who can reach it.

ActLume is not available yet. This page sets out the security design the application must meet and the evidence buyers should see before production access opens.

Required security baseline

Use ordinary, tested SaaS controls.

The design calls for server-side authorisation and managed infrastructure controls. It does not depend on custom encryption keys held by each browser.

01

Identity and authorisation

Expiring and revocable authenticated sessions, role-based access, least privilege, and server-side checks for every organisation-owned action.

02

Tenant and data isolation

Organisation boundaries enforced throughout reads, writes, exports, background work, and audit records rather than by presentation alone.

03

Managed protection

TLS in transit, managed encryption at rest and in backups, managed secrets, sensitive data redaction, and controlled recovery procedures.

04

Audit and recovery

Attributable access and workflow events, bounded retention, tested backups, and recovery evidence appropriate to the data the service handles.

Data handling

Protect report data and explain how the service handles it.

The browser will be a normal authenticated SaaS interface. Authorised report content will travel to the service over TLS and may be stored in the application database under the controls described above.

Minimise exposure

  • exclude credentials from application storage and logs;
  • redact unnecessary incident narrative from telemetry;
  • limit access by organisation and role;
  • make retention and deletion behaviour explicit.

Stay honest about scope

A production security statement must name the controls that are actually deployed, their operational scope, and current exceptions. Those details will be published only when the application release can support them.

External portal

ActLume will not sign in to SRP for you.

The application will help prepare a handoff. It will not hold portal credentials or control the submission page.

  1. 1

    ActLume prepares a reviewed value inside the case workspace.

  2. 2

    The user opens the official portal in a separate top-level context.

  3. 3

    One explicit gesture copies one selected ActLume value.

  4. 4

    The human signs in, pastes, reviews, submits, and confirms the result.

Read the integration boundary

Before production access

Ask for evidence, not a security slogan.

Data map

Categories, purposes, system boundaries, regions, transfers, and retention.

Control evidence

Current implementation and test evidence for access, isolation, backup, and recovery.

Provider register

Actual subprocessors, support paths, incident contacts, and change process.