Trust centre

Security, privacy and accountability as product features

A technically correct system can still create unsafe, unlawful or distrusted work. These are the controls we build in, the failure modes we design against, and the decisions we refuse to automate.

MFA on every accountZero standing privilegePurpose-bound zonesImmutable audit
Identity & access

Zero trust, least privilege, just-in-time

AUTHENTICATION

MFA everywhere

Two of three factors on every account, phishing-resistant preferred: FIDO2 security keys and device biometrics via WebAuthn, authenticator TOTP, or push approval. CJIS-style controls per the SRS non-functional requirements.

AUTHORISATION

Purpose-bound roles

88 role templates scoped by tenant, department, team and assignment. Access decisions evaluate purpose, not just identity — API-IAM-003 returns a policy result on every request.

JIT ACCESS

No standing privilege

Nobody holds permanent keys to protected zones. Elevated access is requested with a purpose, granted time-boxed, fully logged, and expires automatically. Weekly grant sampling.

SEGREGATION

Data zones

Clinical, occupational-health, forensic-psychology, privileged-legal and audit stores each carry independent policies. Cross-zone reads are denied and the denial is itself audited.

TENANCY

Multi-tenancy

An inheritance model, not a folder tree: global policy flows downward; lawful local variations are explicit, versioned and reversible. Feature plans, role templates, rule packs, language and retention all inherit.

SoD

Segregation of duties

No one raises, approves and receives the same purchase; no one certifies their own sentence calculation. Attempts are hard-blocked at source and logged as precedent.

Audit

Append-only, hash-chained, exportable to court

Every screen in XReform carries an audit register. Every audit entry records who, role, device, time, reason and policy result. Corrections preserve the original — nothing is silently rewritten.

  • Evidence packages export with a signed hash manifest for independent verification
  • An export is itself an audited event, with recipient and purpose
  • Residents may request their own record-access history — the right to know who looked
  • Daily integrity sweeps verify sealed exhibits; mismatches raise incidents, not warnings
Audit register · append-only · hash-chained
11:41Countersigned biometric override
Supervisor K. Rao · reason: transposed DOB · ADM-26-04176
DUAL
11:12Clinical note request denied
Custody user · purpose mismatch · protected record
DENIED
10:31Auto-merge attempt blocked
Policy engine · identical demographics · REC-63302
BLOCKED
10:02360° cohort discarded unread
Below confidentiality threshold — partial data would deanonymise raters
PRIVACY
AI governance

Green assists. Amber is watched. Red is never delegated.

Every registered AI use has an owner, a legal basis, an evaluation, an explanation, an override path, an appeal route, monitoring and a kill switch. Green is not "no risk"; amber may be prohibited by local law or policy; red decisions stay human and contestable.

Registry IDUseLaneGovernance
AI-004Spend anomaly ranking
Cohort baselines rank ledger anomalies for accounts review
GREENPrecision audited quarterly (71%) · human decides every action
AI-007Housing placement ranking
Soft-constraint scorer over lawful candidates only
AMBERHard constraints block separately · overrides 11%, all reasoned
AI-011Recidivism cohort analytics
Population outcome model for programme evaluation
AMBERPolicy gate blocks any individual adverse decision
AI-REQ-31Automated segregation triage
Vendor proposal to auto-rank segregation candidates
REDDENIED · disciplinary decisions stay human and contestable
RISK

Automation bias

Staff defer to a score or an alert.

RISK

Surveillance creep

Purpose expands because the data exists.

RISK

Data & equity gaps

Missing context becomes false certainty.

CONTROL

Reasons · override · training

Every ranked output shows why, can be overridden with reasons, and staff are trained that the score is a navigation aid.

CONTROL

Necessity · minimisation · redress

New purposes require a new lawful basis and a redress route — not just a new dashboard.

CONTROL

Provenance · uncertainty · subgroup review

Figures ship with lineage and confidence; quarterly fairness review by language, gender and age.

EDG-61-S · Degraded mode · NV-04
DECLAREcommander + scope
LOCALcount · meds · legal
SIGNtime · actor · source
RESTOREvalidate services
RECONCILEconflicts + gaps
LEARNcause + drill
RECONCILEDFibre cut 19:05 during evening count — degraded mode in 4 min, 312 events reconciled, zero conflicts
Resilience

Offline is an operating mode, not an exception

Count, medicines and release cannot wait for the cloud. Critical work continues locally on the facility edge node with signed evidence, then reconciles conflict-aware when service returns.

  • Count — signed unit sheets with discrepancy resolution before certification
  • Medicines — offline eMAR records administration and omission with reasons
  • Release — live authority by phone protocol plus two-person verification, no exceptions
  • Quarterly drills, including night scenarios; findings become versioned change-sets
Data protection

Minimum necessary, by design

RETENTION

Retention as policy

Audit events immutable for 25 years; CCTV 90 days (evidence until case closes); IoT telemetry 400 days rolling; staff screening 24 months then aggregate only. Deletions are provable events, not silences.

PRIVILEGE

Privilege by architecture

Legal calls, messages and mail are excluded from recording, monitoring and analytics at the infrastructure level. Interview rooms have no recording capability at all.

ANONYMITY

Small-cell suppression

Aggregates render only above thresholds (n ≥ 8 for staff wellbeing, n ≥ 30 for outcome subgroups). Below that, data rolls up or is discarded unread.

RESIDENCY

Residency & sovereignty

Deployable in-country on sovereign cloud or on-premise with facility edge nodes. Tenant data never crosses a jurisdiction boundary without an explicit, versioned configuration decision.

CRYPTO

Encryption

TLS 1.3 in transit, AES-256 at rest, MQTT-TLS for device telemetry, per-tenant key separation, and hash-chained event stores for tamper evidence.

OVERSIGHT

Independent oversight

Ombudsperson read-only access to grievance samples, internal audit sampling on observation proof and access logs, and external notification thresholds for serious incidents.

See also: Privacy policy · Terms & conditions · Service status & SLA

Request the security & DPIA pack

Architecture diagrams, data-flow maps, zone models, retention schedules, AI registry extracts and drill reports — for your security review, not for a brochure.

Request the pack