For security reviewers and procurement
What is in place today, and what is not yet.
Government buyers need a technical answer alongside the ethical one. This page states both, and separates them honestly. Stewardship covers what we refuse to do. This covers how the platform is built and governed.
We do not claim certifications we do not hold. Items marked on the roadmap are exactly that. A security reviewer can request the current overview and we will send it with dates attached.
Filter by status.
Eighteen controls. Ten in place, eight on the roadmap.
Hosting
Managed cloud infrastructure in United States regions, with environment separation between development and production.
Encryption in transit
TLS on every connection to the platform and between services.
Encryption at rest
Storage-layer encryption on all persisted data and backups.
Role-based access control
Access granted by role and scoped to engagement. Least privilege by default.
Multi-factor authentication
Required on all administrative and staff accounts.
De-identification
Direct identifiers are separated at intake. Outputs release only above a suppression threshold.
Suppression and aggregation
No individual-level record leaves the platform, to any client, under any contract.
Community review gate
No findings release before the Data Stewardship Board review window closes.
Retention and deletion
Retention set per engagement. Deletion requests executed and confirmed in writing.
Export
Findings and dashboards exportable in open formats on request.
Audit logging
Access and action logging with client-visible reporting. In build.
Backups and disaster recovery
Documented recovery objectives and a tested restore procedure. In build.
Incident response plan
Written plan with notification timelines and a named responsible owner. In build.
Subprocessor register
Published list of vendors with data access and their review dates. In build.
Penetration testing
Independent annual testing with a summary letter available to clients. Planned.
SOC 2 Type II
Readiness assessment first, then audit. Planned. We will not claim a certification we do not hold.
WCAG 2.2 AA
Accessibility conformance review and remediation across the platform and this site. In progress.
Vulnerability disclosure
A published route for researchers to report issues. Planned.
A tool claiming to show the full picture must mark the edges of its own sight.
The same honesty applies to the platform underneath it. A roadmap item stated as shipped is a finding nobody can rely on.
Just Society Technologies · on disclosureWho owns what, and what happens at the end.
Send this to your reviewer.
We will provide the security overview, data governance summary and accessibility statement without a briefing first.
Request the procurement pack