SECURITY OPERATIONS

Security has to be an operating system, not a policy page.

V11 maps the controls needed as Disease Intelligence moves from synthetic demonstrations toward real institutional software.

Identity

MFA, SSO, session controls, account recovery and privileged-role protection.

Tenant isolation

Every query and mutation scoped to organisation/site permissions.

Secrets

No API keys or SMTP/database credentials in public source or repositories.

Audit

Privileged actions, exports, permission changes and sensitive data access logged.

Application security

CSRF, XSS, SQL injection, rate limiting, dependency scanning and secure uploads.

Data

Classification, encryption, retention, deletion, export and backup policies.

Incident response

Detection, containment, evidence preservation, communications and recovery.

Assurance

Pen testing, secure code review, supplier review and future certification roadmap.