Legal & Trust Center

Security & Information Security Policy

The organisational and technical measures protecting the platform.

Version
1.0
Effective date
17 August 2026
Last updated
17 August 2026
Document owner
the Groundmaster project, with responsibility assigned to its legal and compliance function
Applicable jurisdiction
Portugal, European Union
Permanent URL
https://www.groundmaster.pt/legal/security
This overview describes the security measures we operate. It is a description of practice, not a certification. No claim of formal certification or independent audit is made unless separately evidenced in writing.

1.Identity and access control

  • named accounts with credential hashing and session management, and no shared logins;
  • administrator-controlled provisioning, suspension and permission assignment within each Organisation;
  • role-based authorisation combined with per-page access levels that distinguish read-only from action-capable access;
  • server-side enforcement of authorisation, so restrictions are not dependent on interface behaviour;
  • elevated privileges limited to defined administrative roles and used only where required.

2.Data separation

Each Organisation's data is logically separated and access is enforced at the data layer through row-level rules evaluated against the authenticated identity, in addition to application-level checks. Storage of uploaded documents applies equivalent access restrictions.

3.Encryption

Data in transit is protected with current transport encryption standards. Data at rest, including database contents, uploaded documents and backups, is encrypted by the underlying managed services. Credentials and service secrets are stored in managed secret storage and are never placed in application source.

4.Logging and monitoring

ControlDescription
Audit loggingAuthentication events, record creation and modification, sign-off entries and permission changes are recorded with actor and timestamp
Operational monitoringAvailability, performance and error monitoring with alerting on anomalous conditions
Abuse controlsRate limiting and request filtering to mitigate automated abuse and resource exhaustion
Access reviewPeriodic review of administrative access and of provider access scopes

5.Secure development

  • changes are reviewed before release and validated through automated build and type checks;
  • server-side validation of inputs, with server functions used for privileged operations;
  • dependency and configuration review, with prompt remediation of identified issues by severity;
  • separation of preview and production environments;
  • automated security scanning of database access rules and application configuration.

6.Backups and resilience

Managed backups are taken on a regular cycle, stored encrypted, and subject to restoration testing. Recovery objectives and continuity arrangements are described in the Business Continuity & Disaster Recovery Statement.

7.Personnel and provider controls

Access by our personnel is limited to the minimum required to operate and support the service and is subject to confidentiality obligations. Service providers are assessed before use and engaged under written terms; see the Subprocessors document.

8.Customer responsibilities

  • manage user provisioning, roles, page-level access and timely suspension;
  • protect credentials and enable available authentication safeguards;
  • control which documents and data are uploaded and who may view them;
  • report suspected compromise promptly through the security contact.

9.Reporting a vulnerability

Suspected vulnerabilities should be reported as described in the Responsible Disclosure Policy. Please do not test against live data belonging to other organisations.

Change history

VersionDateChange
1.017 August 2026Initial security overview.
Contact

Questions about this document can be sent to groundmaster.web@gmail.com. Formal legal, privacy, security and regulatory requests should follow the routes described in the legal requests page. Fields shown as bracketed placeholders are pending confirmation by the operating legal entity and do not constitute a statement of fact.

Related documents