Security
OALS is designed with privacy-by-design and enterprise safeguarding controls.
Encryption
Transport uses HTTPS. Sensitive location coordinates are encrypted at rest. Signed, short-lived tokens control image access.
Access control
Role-based access control (ADMIN, INVESTIGATOR, REVIEWER) is enforced server-side. Dashboard APIs require authentication and authorisation.
Audit logs
Critical actions — login, case creation, uploads, link creation, consent events, and role changes — are recorded in append-only audit logs.
Secure storage
Original images are stored privately. Public link pages receive only blurred previews until consent and authorisation succeed.
Data minimisation & retention
We collect the minimum metadata required for security and case integrity. Location retention defaults to the shortest practical period and is configurable by administrators.