Regional SACT Governance Hub

Security and information governance

Security overview

Last reviewed: 19 July 2026

Hosting and encryption

The service is hosted on Microsoft Azure infrastructure in the United Kingdom. Application traffic is protected using HTTPS and production data is stored in a managed PostgreSQL database. HTTP requests are redirected to HTTPS and modern browser security controls are applied through response headers.

Authentication

Approved users can sign in with an NHS or organisational Microsoft account using OpenID Connect with minimal identity scopes, or by a single-use code sent to an active email address already held in the Hub database.

Authorisation

Access is role-based. User identity, Trust, professional group, application roles and tumour-area membership are managed within the service. Inactive accounts cannot sign in.

Audit and accountability

Authentication events, administrative changes and protocol-governance actions are recorded to support accountability, investigation and compliance.

Data minimisation

The Hub is designed for protocol governance rather than patient care records. Patient-identifiable information must not be entered. Email sign-in codes are hashed, expire quickly and can be used only once.

Email security

The domain uses SPF, DKIM and DMARC controls to reduce impersonation risk and improve the authenticity of service email.

Responsible disclosure

Report suspected vulnerabilities, unauthorised access or security incidents to [email protected]. Please provide a clear description, affected URL and reproduction steps, but do not include patient information, credentials or other sensitive data in the initial email. We ask researchers to avoid privacy violations, service disruption, social engineering and destructive testing.

Machine-readable disclosure details are available at /.well-known/security.txt.

Supported browsers

Use a currently supported version of Microsoft Edge, Google Chrome, Mozilla Firefox or Apple Safari with JavaScript and cookies enabled.

Current status

This overview describes the present technical design. Formal penetration testing, organisational assurance and contractual information-governance documentation will be completed before wider regional production adoption.