Skip to main content
Skip to main content
Governance & Trust

Security Policy

The controls we operate to keep the framework and the material you put into it safe, and how to report a problem responsibly.

Version 1.2
Last updated View version history

Maintained by Automated Governance Systems. Last reviewed August 2026. This page is app-owner maintained content, not an independent certification or audit report.

Accounts and access

  • Accounts are individual. Sign-in is by email and password or a supported single sign-in provider; we do not allow anonymous sign-ups.
  • Permissions are role-based. Roles are held separately from user profiles so they cannot be changed from the browser, and staff-only tooling is checked on the server on every request.
  • Database access is governed by row-level security so a signed-in user can only reach their own records and the records shared with them.
  • Session cookies are set as secure, HTTP-only and same-site, and sessions expire.

Data protection in transit and at rest

The site and its APIs are served only over HTTPS. Uploaded evidence and attachments are held in private storage buckets that require an authorised, time-limited link, and our hosting platform encrypts stored data at rest.

Secrets such as API keys live in server-side secret storage. They are read inside server handlers only and are never sent to the browser or written to logs.

Application hardening

  • A content security policy restricts which scripts, frames and media the app may load.
  • Standard protective response headers are set, including strict transport security, frame and content-type protections and a restrictive referrer policy.
  • Input to server functions is validated before use, and webhook payloads are signature-verified before they are trusted.
  • Third-party payment and avatar providers are allow-listed explicitly rather than opened up broadly.

Secure development

Changes go through automated checks in our pipeline: type checking, unit tests, end-to-end tests, accessibility tests, dependency vulnerability scanning and a software bill of materials.

Dependency updates are raised automatically and security patches are prioritised. Database changes are applied as reviewed migrations rather than ad-hoc edits.

Monitoring and incident response

We monitor application errors and audit-trail events for the sensitive parts of the framework. If we become aware of a security incident we contain it, assess the impact, put it right, and record it in our incident register.

Where an incident affects personal data or an in-scope service, we notify affected customers and the relevant authorities within the timescales that apply, including those under UK GDPR and — where in scope — NIS2. Our governance portal carries the incident-reporting workflow we use.

Shared responsibility

We secure the platform, the application and the controls described above. You are responsible for keeping your credentials private, managing who you invite into your workspace, and choosing what personal or sensitive material you upload.

Reporting a vulnerability

Email hello@automatedgovernancesystems.com with enough detail to reproduce the issue. Please give us a reasonable period to investigate and fix before disclosing publicly, and do not access other people's data, degrade the service or run destructive tests. We will acknowledge your report, keep you updated, and credit you if you would like us to.

Version history

Current: v1.2

Last updated . Earlier versions are listed for reference; the newest version is the one that applies.

  1. Version 1.2
    Current

    Added dependency scanning, SBOM generation and NIS2 incident reporting.

  2. Version 1.0

    First published security policy.

Acknowledge this policy

Confirming records the date and time against your account so you and your organisation can evidence that version 1.2 was read.

Questions about this policy?

HELIX — Help Assistant

Ask anything about ALFI + EDIE, governance, or the SAMU apps.

Try HELIX now

Type a question below, or pick a quick prompt to get started.

Quick prompts

HELIX is an AI assistant. Replies may be incomplete or wrong — check anything important with a person.

Try the demo