Each organisation is stored in a separate database and file directory with its own backups.
TLS for all connections. Backups are encrypted with AES-256-GCM. Evidence files, MFA and SSO secrets and paging keys are encrypted at the application level (AES-256-GCM). Hosting region: [EU region].
Single sign-on (OpenID Connect) or password with TOTP two-factor authentication. Server-side sessions with immediate revocation and sign-in rate limiting. Roles with permissions down to individual case fields, restricted cases for embargoed vulnerabilities, and classification of evidence files.
The audit log is linked by a SHA-256 hash chain and checked regularly; administrators are alerted if integrity fails. On the Enterprise plan the chain head is also time-stamped by an external RFC 3161 authority.
Automated encrypted backups with restore testing and optional offsite copies; a background deadline monitor with health checks.
[privacy@example.com]