Security designed around tenant isolation.

How StrongPrivacy keeps one customer's data away from another's, and what each deployment is responsible for.

Authentication

Scrypt password hashing and signed JWT sessions stored in HTTP-only cookies.

Data boundaries

Reviewed private data paths scope queries to the authenticated organization identifier.

Public consent API

Site-origin validation, narrow payloads, and pseudonymous visitor keys.

Application controls implemented in the reviewed build

Reviewed against the application code on 19 September 2026. These are control designs, not an independent audit or certification. Each production deployment must separately verify provider settings, staff access, encryption keys, logging, backups, incident response and vendor contracts.

Private query paths are designed to scope data to the authenticated workspace

Sessions are signed, HTTP-only, and revocable immediately

Connector credentials are encrypted at rest

Supported signed integration messages are authenticated before state changes are applied

The application is designed to delete evidence after the workspace retention window; production scheduling and backup expiry still require operational verification

Scan code restricts navigation and egress to public-address targets

Exports are rate-limited and written to the audit trail

Consent records carry a timestamp, configuration version, and hash-chain evidence