Governance

Information security

Security principles for the Project 360 website and client integration work.

Security principles

Project 360 uses least privilege, separated responsibilities, secure defaults, traceable change and client ownership as design principles. Controls follow the information, threat and operational impact of each engagement.

Website controls

The website uses encrypted transport, restrictive browser headers, server-side enquiry processing, anti-forgery tokens, input validation, request size limits, automated-submission traps and rate limiting. Recipient addresses, mail settings and request-signing secrets stay outside client-side code.

Production configuration should sit above the public web directory where the hosting account supports this layout. Access logs, hosting accounts and mailboxes need multi-factor authentication and periodic review.

Client project controls

Each project records approved data sources, access roles, processing purpose, system owners, retention needs and recovery steps. Proof work uses the smallest practical data scope. Production access starts only after approval and acceptance testing.

Integration designs document data flow, trust boundaries, service accounts, audit records, failure behaviour and exit procedures. High-impact decisions retain meaningful human review.

Suppliers and platforms

Project 360 records relevant hosting, software and AI suppliers for each engagement. Supplier selection considers data location, contractual use, access controls, service history, export options and deletion processes.

Security incidents

Suspected incidents are assessed, contained, documented and escalated according to impact. Client notification follows contractual duties and applicable law. Recovery includes credential rotation, evidence preservation, service restoration and lessons incorporated into controls.

Shared responsibility

Security depends on Project 360 controls, client decisions and supplier operation. Engagement documents assign owners for accounts, approvals, devices, user access, backups, updates, monitoring and incident response.

Report a security concern through the assessment form with “Security report” at the start of the message. Do not include passwords, secret keys or live exploit details in the form.