Security & Information Security Policy
The organisational and technical measures protecting the platform.
- Version
- 1.0
- Effective date
- 17 August 2026
- Last updated
- 17 August 2026
- Document owner
- the Groundmaster project, with responsibility assigned to its legal and compliance function
- Applicable jurisdiction
- Portugal, European Union
- Permanent URL
- https://www.groundmaster.pt/legal/security
1.Identity and access control
- named accounts with credential hashing and session management, and no shared logins;
- administrator-controlled provisioning, suspension and permission assignment within each Organisation;
- role-based authorisation combined with per-page access levels that distinguish read-only from action-capable access;
- server-side enforcement of authorisation, so restrictions are not dependent on interface behaviour;
- elevated privileges limited to defined administrative roles and used only where required.
2.Data separation
Each Organisation's data is logically separated and access is enforced at the data layer through row-level rules evaluated against the authenticated identity, in addition to application-level checks. Storage of uploaded documents applies equivalent access restrictions.
3.Encryption
Data in transit is protected with current transport encryption standards. Data at rest, including database contents, uploaded documents and backups, is encrypted by the underlying managed services. Credentials and service secrets are stored in managed secret storage and are never placed in application source.
4.Logging and monitoring
| Control | Description |
|---|---|
| Audit logging | Authentication events, record creation and modification, sign-off entries and permission changes are recorded with actor and timestamp |
| Operational monitoring | Availability, performance and error monitoring with alerting on anomalous conditions |
| Abuse controls | Rate limiting and request filtering to mitigate automated abuse and resource exhaustion |
| Access review | Periodic review of administrative access and of provider access scopes |
5.Secure development
- changes are reviewed before release and validated through automated build and type checks;
- server-side validation of inputs, with server functions used for privileged operations;
- dependency and configuration review, with prompt remediation of identified issues by severity;
- separation of preview and production environments;
- automated security scanning of database access rules and application configuration.
6.Backups and resilience
Managed backups are taken on a regular cycle, stored encrypted, and subject to restoration testing. Recovery objectives and continuity arrangements are described in the Business Continuity & Disaster Recovery Statement.
7.Personnel and provider controls
Access by our personnel is limited to the minimum required to operate and support the service and is subject to confidentiality obligations. Service providers are assessed before use and engaged under written terms; see the Subprocessors document.
8.Customer responsibilities
- manage user provisioning, roles, page-level access and timely suspension;
- protect credentials and enable available authentication safeguards;
- control which documents and data are uploaded and who may view them;
- report suspected compromise promptly through the security contact.
9.Reporting a vulnerability
Suspected vulnerabilities should be reported as described in the Responsible Disclosure Policy. Please do not test against live data belonging to other organisations.
Change history
| Version | Date | Change |
|---|---|---|
| 1.0 | 17 August 2026 | Initial security overview. |
Questions about this document can be sent to groundmaster.web@gmail.com. Formal legal, privacy, security and regulatory requests should follow the routes described in the legal requests page. Fields shown as bracketed placeholders are pending confirmation by the operating legal entity and do not constitute a statement of fact.