Section 5 · Security Baseline

Cabinet-grade security. Sovereign by design.

The platform is engineered around Government policy, the principle of least privilege, and provable accountability , at every layer, from identity through encryption to data residency.

§ 5.1

Identity & Access

Role-based access control with multi-factor authentication, granular per-document permissions, and delegated authority appropriate to Cabinet sensitivity.

§ 5.2

Audit & Accountability

Comprehensive, tamper-resistant audit logs for user access, workflow actions, document activity, approvals and administrative changes , attributable, time-stamped and exportable.

§ 5.3

Data Protection Baseline

Data protected in transit and at rest using approved cryptographic controls. Defence against unauthorised access, alteration, disclosure and loss.

§ 5.9

Penetration Testing & VA

Pre-production vulnerability assessment and penetration testing covering application, interfaces, authentication controls, administrative functions and supporting infrastructure.

§ 5.11

Encryption Key Management

Keys protecting Government data remain under GoSVG control or a Government-approved arrangement. The Supplier has zero access to production encryption keys unless expressly approved in writing.

§ 5.12

Data Sovereignty & Residency

Cabinet data residency, processing locations and recovery sites operate within Government-approved boundaries, fully aligned with GoSVG policy.

Browser & Access

Universal access, no client install

The platform is compatible with Google Chrome, Safari, Firefox and Microsoft Edge, and provides a fully responsive interface that functions on tablets and smartphones through the browser , without requiring a separate native mobile application for core functionality.

The preferred Government technology stack will be confirmed at the Pre-Bid meeting.