Security overview
This page describes controls that are actually in place today. It is maintained by the service operator and is not an independent certification or audit.
Effective date: To be confirmed before public launch
Last updated: 28 July 2026
Version: Draft 0.1
Status: Published
Operated by: Mohammad Asif, trading as PublicVoiceShield, United Kingdom
This document is provided for information only. It is not legal advice and no guarantee of compliance is given. Designed to support UK GDPR compliance, subject to organisational use, configuration and legal review.
Access and authentication
- Email and password sign-in with email verification, provided by our managed authentication service.
- Password reset links are single-use and time limited.
- Every application page that shows organisation data requires a signed-in session.
Organisation isolation
- Database-level row access rules scope every record to the organisation that owns it.
- Membership checks are evaluated in the database against the signed-in user, not against values supplied by the browser.
- The server independently verifies active membership before any analysis or write.
AI keys and secrets
- The AI provider key is held as a server-side secret and is never sent to the browser.
- AI calls are made only from server-side code.
- Provider errors are not returned verbatim to users.
Audit integrity
- Analyses and analysed comments cannot be updated or deleted from the application.
- Human decisions are recorded as new append-only rows.
- Both the original AI suggested reply and any edited version are preserved.
Shared responsibility
We secure the platform. Your organisation is responsible for who it invites, the roles it grants, the content it submits and the decisions it takes. Report a security concern to [Support contact email — TO BE CONFIRMED].