Effective 24 July 2026Customers, security reviewers and EmpowerNotes personnel
Core controls
- Organisation-level data separation enforced in the database.
- Role-based access and least-privilege permissions.
- Multi-factor authentication for privileged access.
- Encryption in transit and security controls provided by contracted hosting services.
- Private server-side handling of service credentials and API keys.
- Audit logging, monitoring and investigation of suspicious activity.
Customer responsibilities
- Assign the minimum access needed for each worker.
- Use individual accounts and do not share credentials.
- Review staff, house and participant assignments regularly.
- Remove or suspend access promptly when responsibilities change.
- Report suspected compromise without delay.
Privileged and developer access
Administrative and developer access is restricted, logged and used only for authorised support, security, maintenance or legal purposes. Production access should require strong authentication and be reviewed regularly.