Least privilege
Access should be scoped to what people and systems need to perform a defined task.
Security
We design around least privilege, data minimisation, traceability and clear operational boundaries. Product-specific controls and assurance information will be published as each product becomes available.
Access should be scoped to what people and systems need to perform a defined task.
Product design should avoid collecting or retaining information that is not needed for the workflow.
Important actions should be understandable after the fact, with ownership and context preserved.
Default behaviour should favour narrower access, explicit configuration and clear operational boundaries.
This page describes current design principles for the public website and developing products. Product-specific controls, assurance information and operational documentation will be published as each product becomes available.
Please report suspected security issues to [email protected]. Avoid including secrets, credentials or sensitive personal information unless it is necessary to explain the issue.
Email security contact