Security & trust
Built for the responsibility of public data.
Personnel records, service books, payroll and citizen applications are among the most sensitive data a state holds. These are the controls we build into the platforms we deliver, and the constraints we design them against.
What these claims are, and are not
These are engineering capabilities we build into the platforms we deliver. They are not certifications, accreditations or compliance attestations — we hold none, and we do not claim any government approval or endorsement.
Controls
What we build in.
Applied across every platform we deliver rather than added per project, so a second module inherits the same model as the first.
Role-based access
Permissions follow the post, not the person — so a transfer moves access with it.
Permission management
Granular rights per module, branch and record, administered in-app.
Audit trails
Who changed what, when, and from where — written for every state change, not just logins.
Secure authentication
Session handling, password policy and lockout built to current practice.
Multi-factor authentication
Second factor available per role, and enforceable for privileged accounts.
Data encryption
Encrypted in transit, and at rest for the stores that hold personal data.
Backup and recovery
Scheduled backups with a restore procedure that gets tested, not assumed.
Activity history
Every record carries its own movement history, readable by authorised staff.
Access control
Rules at the row and field level, so a branch sees its own establishment.
Security monitoring
Anomalous access surfaced to administrators with the context to act on it.
Constraints
What changes between one government and the next.
Three of these are security decisions before they are anything else, and all three are settled during assessment rather than discovered at deployment.
Data residency and sovereignty
Where public data is legally allowed to sit varies by country, and frequently by classification within a country. It is an architecture decision, not a hosting preference.
- On-premise and national data centres
- Sovereign and government cloud
- Air-gapped environments
- Cross-border transfer restrictions
Accessibility obligations
Public-sector accessibility is generally a legal duty rather than a quality goal, and the applicable standard differs by jurisdiction even where the substance overlaps.
- WCAG 2.2 AA
- EN 301 549
- Section 508
- National accessibility regulations
Records and retention law
What must be kept, for how long, and what happens at the end is set by archival and disclosure law — which makes retention part of the data model rather than a cleanup job.
- Statutory retention schedules
- Archival transfer obligations
- Freedom-of-information regimes
- Legal hold and disclosure
UXAtom GovTech
Ask us how we would secure your platform.
Bring the constraints — where data must sit, which identity scheme applies, what your auditor asks for — and we will tell you what we would build and what we would not.
Or email us directly at hello@uxatom.com