Pre-release document — not yet in force
MW Compliance Hub is not yet open to customers and does not hold information about real people. These pages are published early so they can be read and challenged before anyone signs up. They take effect only when the platform is released for real use, and some points below are still outstanding — they are shown as outstanding rather than filled in with a guess.
What is in place
- Each organisation's records are separated at the database level, so one organisation cannot read another's information even if the application misbehaves.
- Every screen and action is checked against the permissions of the signed-in account, on the server rather than in the browser.
- Access decisions fail closed: if a permission or an organisation cannot be established, access is refused rather than allowed.
- Evidence records — audits, approvals, incidents, exports — are written to an append-only trail that cannot be edited or partly deleted. Corrections are made by adding a superseding entry.
- Sign-in attempts are rate-limited and locked out after repeated failures, and security events are recorded.
- Traffic is encrypted in transit, and the database is encrypted at rest by the hosting provider.
- Exports are recorded, so it is always possible to see who took information out and when.
- Every change to the platform goes through automated checks covering permissions, data separation, secrets and dependencies before release.
What we do not claim
Still outstanding
- Recovery from loss has not been proven. No backup has been restored and timed, so we state no recovery time or maximum data-loss figure and give no recovery guarantee.
- We hold no independent certification such as ISO 27001 or SOC 2, and have not had an independent audit or penetration test.
- Two-step sign-in for privileged accounts is planned and not yet enforced.
- Our hosting provider's backup arrangements and incident-notification timescales are not yet confirmed to us in writing.
Customers may ask us for our written security description and evidence pack. We do not offer live access to systems holding another organisation's information.
Reporting a problem
If you believe you have found a security weakness, write to the Data Protection Contact, MW Integrated Care Consultancy Ltd at 71–75 Shelton Street, London, WC2H 9JQ, United Kingdom. Please do not test against other people's information. We will confirm receipt, investigate, and tell you the outcome.
