Skip to main content

Trust and security

Sensitive building information needs a deliberate access boundary.

RubblePass is designed to keep public education, permissioned project work and accountable review distinct as the prototype moves toward live validation.

This page describes the current prototype position and design commitments. RubblePass does not claim an independent security certification or completed third-party penetration test.

Current safeguards

Start with identity, permissions and minimum necessary disclosure.

Application layer

Authenticated sessions

Prototype workspaces require a signed-in account. Passwords are stored as hashes and sessions are checked on protected routes.

Scoped access

Organization roles

Workspace membership and role information are used to determine the actions available to a signed-in user.

Data minimization

Private details stay restricted

Public material views should avoid exact private locations and commercial records unless an authorized owner intentionally discloses them.

Hosted service

Managed infrastructure

The prototype uses established hosting and PostgreSQL services. Provider configuration and operational controls remain part of production readiness review.

Data path

Classify first, then grant only the access the workflow needs.

  1. 01

    Classify

    Identify public, organization, project, personal, location and commercially sensitive fields.

    Data owner
  2. 02

    Authorize

    Invite the required person into the right organization or project role.

    Organization owner
  3. 03

    Use

    Limit access to the decision and time period for which it was granted.

    Named purpose
  4. 04

    Review

    Check memberships, privileged actions and unexpected access during the validation.

    Operational control
  5. 05

    Remove

    End access and apply the agreed retention or deletion action when the need ends.

    Closeout

Production boundary

Controls we will not imply before they are evidenced.

No absolute security promise

No online service can state that unauthorized access is impossible under all circumstances.

No unverified encryption claim

Transport, storage and backup claims should name the applicable provider and configuration before publication.

No certification by association

A hosting provider’s certification does not automatically certify the RubblePass application or operating process.

No silent production data

Live project content should not be onboarded until scope, access, retention, incident contact and backup expectations are agreed.

Start with evidence

Need a control explained for a proposed validation?

Ask about the data, role, hosting or review boundary that matters to your organization. We will distinguish current controls from planned work.