Security and information governance
Security overview
Last reviewed: 19 July 2026
Hosting and encryption
The service is hosted on Microsoft Azure infrastructure in the United Kingdom. Application traffic is protected using HTTPS and production data is stored in a managed PostgreSQL database. HTTP requests are redirected to HTTPS and modern browser security controls are applied through response headers.
Authentication
Approved users can sign in with an NHS or organisational Microsoft account using OpenID Connect with minimal identity scopes, or by a single-use code sent to an active email address already held in the Hub database.
Authorisation
Access is role-based. User identity, Trust, professional group, application roles and tumour-area membership are managed within the service. Inactive accounts cannot sign in.
Audit and accountability
Authentication events, administrative changes and protocol-governance actions are recorded to support accountability, investigation and compliance.
Data minimisation
The Hub is designed for protocol governance rather than patient care records. Patient-identifiable information must not be entered. Email sign-in codes are hashed, expire quickly and can be used only once.
Email security
The domain uses SPF, DKIM and DMARC controls to reduce impersonation risk and improve the authenticity of service email.
Responsible disclosure
Report suspected vulnerabilities, unauthorised access or security incidents to security@sacthub.co.uk. Please provide a clear description, affected URL and reproduction steps, but do not include patient information, credentials or other sensitive data in the initial email. We ask researchers to avoid privacy violations, service disruption, social engineering and destructive testing.
Machine-readable disclosure details are available at /.well-known/security.txt.
Supported browsers
Use a currently supported version of Microsoft Edge, Google Chrome, Mozilla Firefox or Apple Safari with JavaScript and cookies enabled.
Current status
This overview describes the present technical design. Formal penetration testing, organisational assurance and contractual information-governance documentation will be completed before wider regional production adoption.