UK GDPR
DSAR Case-Management Workflow
Article 15 (access) and Article 17 (erasure) requests are handled through a structured case-management workflow. Statutory one-month deadlines are tracked automatically. Identity verification and Director sign-off on erasure are enforced.
Core workflow live. Object-storage hardening in progress — some attachment handling is still being strengthened.
Integrity
Dedicated Audit Trails
Sensitive platform and operational actions — record access, searches, support sessions, staff bypasses — are written to dedicated audit trails. Selected evidentiary records carry database-level immutability controls (DB triggers); coverage is being expanded and verified across the remaining modules.
Safety
Mandatory Escalation Routing
Reports involving CSAM, terrorism, credible threats, or court orders are automatically routed to the platform Trust, Safety & Integrity queue. Community Directors and staff cannot suppress, close, or redirect these reports — the pipeline is enforced at platform level.
Governance
Sanction Ladders & Appeals
Two parallel five-rung sanction ladders — one for platform users, one for communities. Each rung has documented authority, a mandatory cooling-off period, and a formal appeal window. No one is removed or suspended without a documented trail.
Authority
Sign-Off Authority & Director Break-Glass
Consequential actions are gated by the role registry — only the correct authority can take them. A Director break-glass mechanism exists for genuine emergencies; every invocation is logged with a mandatory reason (minimum 50 characters), timestamped and irrevocable.
Records
Compliance, Risk & Data Registers
A live breach register (Article 33/34 notification timelines tracked), data retention schedule, sub-processor register, ICO correspondence log, and DPIA register — each maintained as a structured record in the platform.
Regulation
Online Safety Act Reporting
A first-party "Report a Problem" tool surfaces in every community. Reports are routed into the mandatory escalation pipeline for triage, with full audit trail. The platform is structured for OSA obligations — regulated services can meet their transparency requirements.
Age
Age Gating
A minimum age of 13 is required to hold a platform account, in line with UK data protection law (GDPR Article 8 and UK GDPR equivalent). Subscriptions require an age declaration of 18 or over. The age gate is enforced during mandatory onboarding — before ordinary platform access — and again at the subscribe flow.
Isolation
Multi-Tenant Data Isolation
Every tenant-scoped query filters on the community's own tenant ID, and automated cross-tenant test suites run on every merge. Independent security reviews (May–July 2026) found no cross-tenant data leak.
Application-level scoping is the live isolation layer. Database-level row-level security is deployed as a staged backstop and is still being hardened before it is enforced independently of the application.