Tenant and role separation
Organizations, clients, projects, cases and evidence are restricted by tenant scope and permission. Platform access requires separate super-administrator authorization.
Protecting accounts, tenant data, evidence and the public service surface.
Organizations, clients, projects, cases and evidence are restricted by tenant scope and permission. Platform access requires separate super-administrator authorization.
Passwords are stored as salted hashes. Login lockout, email verification, optional authenticator-based two-factor authentication and revocable sessions are supported.
Production operation requires HTTPS, secure cookies, strict origin checks and security headers. Public forms use bot traps, signed timing checks and persistent rate limits.
Original files and generated exports use SHA-256 manifests. Technical source material is kept separate from analysis and legal notes.
Health checks, backups, recovery tests, provider diagnostics and audit records are part of the production readiness process.
Potential security issues should be reported privately to kontakt@borban.de with sufficient detail for reproduction.