Identity
MFA, SSO, session controls, account recovery and privileged-role protection.
V11 maps the controls needed as Disease Intelligence moves from synthetic demonstrations toward real institutional software.
MFA, SSO, session controls, account recovery and privileged-role protection.
Every query and mutation scoped to organisation/site permissions.
No API keys or SMTP/database credentials in public source or repositories.
Privileged actions, exports, permission changes and sensitive data access logged.
CSRF, XSS, SQL injection, rate limiting, dependency scanning and secure uploads.
Classification, encryption, retention, deletion, export and backup policies.
Detection, containment, evidence preservation, communications and recovery.
Pen testing, secure code review, supplier review and future certification roadmap.