Security is an ongoing process. This overview describes current design controls at a high level and does not create a separate warranty or certification.
Tenant isolation
STATIQOPS is designed to separate department data and enforce tenant-scoped access on the server. Department and station scoping limit what authorized users can see and manage.
Role-based access
Organizations can use defined roles and permissions so frontline members, department administrators, and platform administrators receive different levels of access. Administrative operations are protected separately from member workflows.
Authentication and sessions
The production application supports authenticated department and platform sessions, session revocation, login throttling, password reset workflows, and security-event logging.
Production infrastructure
The production service uses HTTPS and a PostgreSQL-backed infrastructure. Application secrets and production credentials are managed as deployment environment variables rather than published in source code.
Auditability and backups
Operational and security logging are used to support troubleshooting and accountability. Production backup and restore procedures are part of the platform's operational-readiness design.
Customer responsibilities
Customers should use unique passwords, promptly remove unnecessary access, assign roles carefully, maintain accurate department policies, and report suspected account compromise promptly.
Vulnerability and security inquiries
If you believe you have found a security issue, use the website contact form and clearly identify the message as a security report. Do not access, alter, or retain data that does not belong to you.
