Security

OALS is designed with privacy-by-design and enterprise safeguarding controls.

Encryption

Transport uses HTTPS. Sensitive location coordinates are encrypted at rest. Signed, short-lived tokens control image access.

Access control

Role-based access control (ADMIN, INVESTIGATOR, REVIEWER) is enforced server-side. Dashboard APIs require authentication and authorisation.

Audit logs

Critical actions — login, case creation, uploads, link creation, consent events, and role changes — are recorded in append-only audit logs.

Secure storage

Original images are stored privately. Public link pages receive only blurred previews until consent and authorisation succeed.

Data minimisation & retention

We collect the minimum metadata required for security and case integrity. Location retention defaults to the shortest practical period and is configurable by administrators.