Security designed around tenant isolation.
How StrongPrivacy keeps one customer's data away from another's, and what each deployment is responsible for.
Authentication
Scrypt password hashing and signed JWT sessions stored in HTTP-only cookies.
Data boundaries
Reviewed private data paths scope queries to the authenticated organization identifier.
Public consent API
Site-origin validation, narrow payloads, and pseudonymous visitor keys.
Application controls implemented in the reviewed build
Reviewed against the application code on 19 September 2026. These are control designs, not an independent audit or certification. Each production deployment must separately verify provider settings, staff access, encryption keys, logging, backups, incident response and vendor contracts.
Private query paths are designed to scope data to the authenticated workspace
Sessions are signed, HTTP-only, and revocable immediately
Connector credentials are encrypted at rest
Supported signed integration messages are authenticated before state changes are applied
The application is designed to delete evidence after the workspace retention window; production scheduling and backup expiry still require operational verification
Scan code restricts navigation and egress to public-address targets
Exports are rate-limited and written to the audit trail
Consent records carry a timestamp, configuration version, and hash-chain evidence