Secure architecture
Define trust boundaries between interfaces, services and storage. Separate product data and avoid assuming that an internal component is automatically trusted.
SECURITY & TRUST
AANSC’s security direction centers on deliberate access, limited data exposure and reviewable system behavior. Controls must be verified for each product and deployment.
Define trust boundaries between interfaces, services and storage. Separate product data and avoid assuming that an internal component is automatically trusted.
Identify the user or service, then evaluate what it is allowed to do. Use least privilege and scope permissions to the task.
Protect information in transit and at rest using appropriate, maintained mechanisms. Key management and recovery need as much attention as encryption itself. No certification or universal control coverage is claimed here.
Collect information required for the workflow, keep unrelated contexts separate and limit retention. Use local processing where it provides a meaningful privacy benefit.
Maintain dependencies, restrict operational access and establish deployment and recovery procedures. Reliability and security must be tested in the environment actually used.
Record operational events that support investigation while avoiding credentials, clinical content and unnecessary personal information in logs.
Review assumptions during architecture, inspect changes during implementation and validate critical behavior before deployment. Threat models should evolve with new integrations.
Investigate reports, contain affected access, preserve relevant evidence and communicate appropriately. Report suspected issues through the contact page without including passwords or sensitive records.