Security & trust

Security as a design property

Regisia is built for organisations whose data decisions are scrutinised. This page describes what the platform actually does — not a wall of badges.

Separation

Your organisation's data is yours alone

Regisia keeps every customer organisation strictly separated. That separation is enforced in the platform's data model and on every request the server handles — it is not a filter applied in the browser, and it is not a setting an administrator could get wrong.

The same rule reaches into search and the AI Assistant: retrieval is confined to your organisation's own content before anything is ranked or suggested, so no answer, score or "did you mean" is ever informed by another organisation's material.

Access

Access is deliberate, scoped and revocable

Server-held sessions

Sign-in produces a server-side session in a secure, HttpOnly cookie. No credential or token is ever stored in the browser where a script could read it.

Immediate revocation

Because sessions live on the server, deactivating an account ends its access at once — not when a token expires.

Granular roles

Staff, managers and administrators each hold defined permissions, enforced by the platform on every request rather than by hiding buttons.

Scoped oversight

A manager's reporting is derived from their recorded team responsibilities. There is no parameter to widen it.

Careful sign-in behaviour

Login failures are deliberately uninformative, so the sign-in screen cannot be used to discover who works where.

Request forgery protection

Every state-changing request is CSRF-protected in addition to being authenticated and authorised.

Evidence

Records you can rely on

Append-only acknowledgements

Acknowledgement records are written once, against a named person and a specific document version, and are protected against later editing or deletion.

Attributed audit trail

Administrative actions inside your organisation are recorded chronologically, each naming the person who performed it.

Operator transparency

If a Regisia operator views your organisation for support, that access is read-only, time-limited and written into your audit trail, attributed to the named operator.

Scanned uploads

Every file uploaded to the document library is scanned for malware before it is stored.

Operations

Platform hygiene

  • Encrypted in transit. All traffic is served over TLS, with strict transport security enforced.
  • Least privilege internally. The platform's own services run under narrowly-granted accounts; production is a separate environment with its own credentials, isolated from testing.
  • Tested as a security property. Organisation separation, permission enforcement and session behaviour are covered by automated tests that run before changes ship — they are treated as product features, not best efforts.
What we don't claim

No borrowed badges

You will not find certification logos on this page that we cannot substantiate. Where your governance process requires a security questionnaire, due-diligence review or contractual commitments, we will work through them with you directly — ask when you book a demonstration.

Put your security questions to us.

The demonstration is a working session — bring your information-governance colleagues.