← CRA IncidentOps
Template document. Before publication the operator must complete the bracketed fields and obtain legal review.

Security and Data Protection

Isolation

Each organisation is stored in a separate database and file directory with its own backups.

Encryption

TLS for all connections. Backups are encrypted with AES-256-GCM. Evidence files, MFA and SSO secrets and paging keys are encrypted at the application level (AES-256-GCM). Hosting region: [EU region].

Access

Single sign-on (OpenID Connect) or password with TOTP two-factor authentication. Server-side sessions with immediate revocation and sign-in rate limiting. Roles with permissions down to individual case fields, restricted cases for embargoed vulnerabilities, and classification of evidence files.

Traceability

The audit log is linked by a SHA-256 hash chain and checked regularly; administrators are alerted if integrity fails. On the Enterprise plan the chain head is also time-stamped by an external RFC 3161 authority.

Continuity

Automated encrypted backups with restore testing and optional offsite copies; a background deadline monitor with health checks.

Report a vulnerability

[privacy@example.com]