01
Identity and authorisation
Sessions must expire and support revocation. Access must follow roles and least privilege, with server-side enforcement on every action.
Security & data protection
ActLume's production requirements cover authenticated sessions, tenant isolation, server-side authorisation, managed encryption, audit records, backups, and sensitive-data redaction. Each control requires implementation and verification before customer use.
The required security baseline
Product policy keeps authorisation on the server and infrastructure protection managed. The browser boundary is a normal signed-in interface, not a key vault.
01
Sessions must expire and support revocation. Access must follow roles and least privilege, with server-side enforcement on every action.
02
The organisation boundary must cover reads, writes, exports, background jobs, and audit records, with reciprocal isolation tests before customer use.
03
Production policy requires current approved TLS, managed encryption at rest and in backups, managed secrets, sensitive-detail redaction, and controlled recovery.
04
Access and workflow events must be attributable. Retention must be bounded, and backup and recovery behavior must be tested before customer use.
Data handling
The production design stores report content in the service database and applies the control requirements above. Deployment evidence must establish the actual protection.
Exposure kept small
The boundary stays explicit
The security record must identify each control, its operational scope, the responsible owner, relevant test evidence, and any exception that changes customer protection.
External portal
The product design keeps portal credentials and the submission page under the authorised filer's control through a deliberate handoff.
The case workspace design prepares reviewed values for handoff.
Your filer opens the official portal in its own browser tab.
The copy-assist boundary permits only one selected value per deliberate user gesture.
Your filer signs in, pastes, reviews, submits, and confirms the result.
For your security review
Security reviews run on evidence, not slogans. These are the disclosures required before assurance or procurement review can rely on a control statement.
The data categories, purposes, system boundaries, regions, transfers, and retention that apply to the service.
Same-release evidence for the access, isolation, backup, and recovery controls described above.
The processors in use, support access paths, incident contacts, and the approved change-notification process.
Next step