Authentication, roles and revocation
Authenticated web and mobile operations resolve the current user and organisation before protected actions. Canonical roles and permissions restrict administrative and operational capabilities. Owners and authorised administrators can revoke organisation access.
Tenant separation
Customer data is keyed and queried by organisation and, where relevant, workspace. Protected actions and storage services apply organisation-scoped checks. Tenant-isolation tests cover sensitive areas, but no public certification is claimed.
Audit trails
Important organisation, storage, export, sharing and workflow actions create audit or immutable event records. These support investigation and evidence integrity and are not presented as a substitute for customer oversight.
Private documents and controlled sharing
Customer files are catalogued against organisation ownership and stored in private object storage unless a specific managed public asset is intended. Protected files use authorised delivery or short-lived signed access. Evidence shares can be read-only, time-limited and revocable.
Mobile and offline data
The mobile app can store operational data in application storage for offline work and uses platform secure storage for authentication material where supported. Customers should require device passcodes, timely OS updates and rapid access revocation. We do not claim that every offline database field is independently encrypted.
Transport and service boundaries
Production endpoints are intended to be delivered over HTTPS. First-time authentication, authoritative status, uploads, PDF generation, notification delivery and some approvals require online services even when capture is offline-capable.
Reliability, recovery and deletion
Asynchronous workers use durable job records, retries and scheduled recovery for supported workflows. Organisation exports can be prepared before the implemented pending-deletion lifecycle. Backup and disaster-recovery commitments require separate operational verification and are not promised here.
Security and vulnerability reporting
Report suspected unauthorised access, data exposure or a vulnerability through the support contact below. Provide a clear description and safe reproduction details, but do not access data that is not yours, disrupt the service or publicly disclose sensitive details before we can investigate.
Contact DutyStack
Email support@dutystack.co.uk