Access controls
Current
Application records use role- and ownership-based access rules where configured. Administrative screens and sensitive inquiry records are restricted to administrators.
Administrative boundaries
Current
Administrative data and public assessment experiences are separated through application roles and entity access rules.
Credential handling
Platform-provided
Authentication is handled by the application platform. Beacon2Beacon does not ask users to place passwords or API credentials into assessment or contact forms.
Server-side secrets
Planned as needed
No custom third-party API credential workflow is currently claimed. Future external-service secrets are intended to remain in server-side secret storage rather than page code.
Audit and activity records
Under review
The data model supports audit and activity records, but comprehensive automated security-event coverage has not yet been verified.
Data transmission
Platform-managed
Transport is provided by the hosting platform. Beacon2Beacon has not independently published a formal transport-control certification.
Data storage
Platform-managed
Application records are stored through the platform database and file services. Retention automation and independent control attestations remain under review.
Service-provider boundaries
Current
Hosting, authentication, database, and storage capabilities may be delivered by platform providers; their controls are not represented as Beacon2Beacon certifications.
Abuse prevention
Partial
Form validation and access rules are active. Additional monitoring, rate controls, and formal abuse-response procedures remain under review.
Incident reporting
Current intake
Security concerns can be documented through the Contact form by selecting Security concern. No separate emergency-response channel is currently published.
Responsible disclosure
Under review
A formal disclosure policy and response timeline are planned. Reports submitted through the Contact form will provide the current documented intake path.

