VCFease
Current areaVCFease
VCFeaseSECURITY & TRUST CENTRE

Privacy boundaries are part of the operating model

The current pilot already uses server-side access checks, durable D1/R2 storage, restricted review gates and suppressed public reports. The Microsoft production target strengthens identity, network, database and monitoring controls before public rollout.

Identity & least privilege

Role, organisation membership, assignment and purpose are checked on the server. Staff and external identities remain separate in the production architecture.

Tenant isolation

Every organisation record is workspace-scoped. Production moves to tenant_id plus Azure SQL row-level security and automated cross-tenant tests.

Five information zones

Public, account-private, organisation-confidential, restricted and sanitised analytics have visibly different handling and publication rules.

Human Review

Imports, partner updates, AI suggestions, aggregate promotion, public reports and sensitive exports require an authorised decision.

Observatory disclosure control

Only reviewed aggregates enter place reporting. Small groups are server-suppressed and source rows are never returned to public views.

Microsoft-first production

Entra External ID, workforce Entra, Azure Front Door/WAF, API Management, Container Apps, Azure SQL, Blob, Service Bus and managed identities form the rollout target.

Restricted-data AI exclusion

Safeguarding, children, health, identity documents and raw restricted cases are not sent to general AI. Other text is minimised and tokenised first.

Audit, recovery & incident readiness

Views, changes, exports, role changes and publication are auditable. Production targets tested backups, incident ownership and a UK regional recovery plan.

PUBLIC PILOT RELEASE GATE

Required before wider live use

DPIA, controller/processor terms, ROPA and retention schedule approved

Entra tenant, MFA/Conditional Access and break-glass controls configured

Independent penetration and accessibility tests passed

Upload malware scanning, audit export and alerting operational

Backup restore and incident-response exercises evidenced

Organisation network access kept free; any future paid Aspire service separately approved and enabled