The registry holds the identifiers on which member institutions base financing decisions. This policy summarises the controls that protect it. Members carrying out security due diligence can request our detailed control documentation from security@supersaveprotocol.com.
01 Governance
- A named individual is accountable for information security and reports to the board.
- Security policies are reviewed at least annually, and after any material incident or architectural change.
- Risk assessments are documented, owned and tracked to closure.
- Security requirements are considered at design time for every new module — not bolted on before launch.
02 Access control
- Role-based access control across twelve institutional roles, each with an explicit ability set.
- Organisation scoping: a user sees their own institution's records and only the registry-wide fields the check requires.
- Least privilege by default; elevation requires approval and is logged.
- Two-factor authentication for registry accounts.
- Password hashing with a modern one-way algorithm, enforced rotation, and lockout after repeated failed attempts.
- Idle session timeout and session invalidation on password change.
- Quarterly access reviews by member administrators, with our support.
- Administrative access to production is restricted, individually attributed and logged.
03 Data protection in transit and at rest
- TLS 1.2 or above for all connections, with modern cipher suites and HSTS.
- Encryption at rest for databases, file storage and backups.
- Document fingerprints computed with SHA-256; credentials never stored in reversible form.
- Secrets held in a managed secret store, rotated on a defined schedule and on personnel change.
04 Application security
- Parameterised database queries and output encoding as standard practice.
- Cross-site request forgery tokens on every state-changing request.
- Security headers including content type options, frame options and referrer policy.
- Input validation server-side, never relying on client-side checks alone.
- Dependency scanning with defined remediation timescales by severity.
- Code review before merge; no direct changes to production.
05 Logging and monitoring
- Append-only audit log capturing actor, organisation, role, action, timestamp and IP for every registry action.
- Authentication events logged separately, including failures and lockouts.
- Alerting on anomalous access patterns, privilege changes and bulk data access.
- Logs protected against alteration and retained for seven years.
06 Resilience and continuity
- Automated backups with encryption, held on a 35-day rolling window.
- Restore testing on a defined schedule, with results recorded.
- Documented recovery point and recovery time objectives, reviewed annually.
- Business continuity and disaster recovery plans exercised at least annually.
07 Personnel security
- Background checks proportionate to role, where lawful in the jurisdiction.
- Confidentiality undertakings for all personnel and contractors.
- Security and data protection training on joining and annually thereafter.
- Access revoked on the day a person leaves or changes role.
- Clear desk and device encryption requirements for anyone handling production data.
08 Supplier security
Every supplier with access to registry data is assessed before engagement and re-assessed periodically. Contracts include security obligations, breach notification and audit rights no less protective than those we owe Members. Current sub-processors are published at Sub-processors.
09 Testing
- Independent penetration testing at least annually and after significant architectural change.
- Findings triaged by severity with defined remediation timescales and tracked to closure.
- A summary report is available to Members under confidentiality on request.
- Vulnerability reports from external researchers are welcomed under the Responsible Disclosure Policy.
10 Incident response
- Detect and triage. Incidents are classified by severity within one hour of detection.
- Contain. Immediate action to limit impact, including suspending access where necessary.
- Notify. Affected Members are told without undue delay, and within 48 hours where personal data is involved. Supervisory authorities are notified within 72 hours where the threshold is met.
- Eradicate and recover. Root cause removed, service restored, integrity verified.
- Review. A blameless post-incident review with corrective actions owned and tracked.
Report a suspected incident to security@supersaveprotocol.com.
Questions about this document?
Write to legal@supersaveprotocol.com, or to Super Save Protocol Ltd, 207 Regent Street, London, W1B 3HH, United Kingdom. You can also see all our legal documents.