How Indacas protects your data
This is the short version for researchers doing due diligence and participants wondering where their answers go. The fuller public statement is on our security page.
Where your data lives
All respondent data is stored by default in DigitalOcean’s London region, in the United Kingdom. If your institution requires a different place of data residency, that’s an Enterprise arrangement — talk to us.
Encryption
Data is encrypted in transit over HTTPS, with HSTS enforced. TLS terminates at the edge and internal service traffic stays on private networks. Data in our databases is encrypted at rest with Linux Unified Key Setup.
Who can reach it
- The platform API has no public route. It sits on an internal network reachable only by the application itself, and administrative interfaces are restricted to named engineers.
- Access is by role. Editing, participant management, bulk export and audit viewing are each restricted to specific roles. Fields marked sensitive require a further privilege before they can be exported.
- Accounts are protected. Passwords are hashed by the identity service, a verified email address is required before sign-in, sessions expire after 24 hours, and sign-in responses never reveal whether an address is registered. See Two-factor authentication.
Audit trail
Creates, updates and deletes are recorded with actor, timestamp, target, IP address and user agent, written centrally so no code path can skip them. Bulk exports are logged explicitly as data leaving the platform. Study and organisation audit logs are readable in the app by authorised users — you don’t have to ask us for them.
Consent you can evidence
Consent statements are versioned, and each captured consent stores a hash of the exact text shown, with an optional typed signature. Revocation is timestamped rather than deleted, so the record of what someone agreed to, and when they changed their mind, survives. See Consent.
Collecting less
Where we can avoid holding something, we do. Date of birth is never stored — only a confirmation that someone meets a study’s minimum age.
Abuse protection
Request rate limits are partitioned by authenticated user or client address, and new anonymous survey responses must pass a bot check.
Certification — the honest position
DigitalOcean’s cloud platform holds SOC 2 Type 2 and SOC 3 attestations covering the infrastructure underneath us. Those are theirs, not ours.
Indacas itself holds no certifications yet. We’re working towards the NHS Data Security and Protection Toolkit and Cyber Essentials, with a DCB0129 clinical safety case and a formal WCAG 2.1 AA accessibility audit to follow. We’ll list each one here once it’s complete, and not before.
If your institution needs more for its own review, we keep written documentation on data flow and residency, access control and audit, retention and deletion, business continuity, incident response and our suppliers. Ask and we’ll send it.
Found a vulnerability?
Tell us through the contact form and we’ll get back to you. Please give us a reasonable window to fix it before disclosing publicly.