Statement

Security

Last updated 4 September 2026

How Remit protects agency information, and what remains to be certified before production use.

Access

Sign-in with the agency's Microsoft Entra ID account (single sign-on with the agency's own multi-factor policies) or an agency-issued password. No self-registration. Sessions expire and are revoked on sign-out.

Separation between agencies

Every database query is scoped to the signed-in user's agency. Uploaded files are stored outside the web root and served only through authenticated, agency-checked routes.

Audit

Every create, update, approval, export, sign-in and AI call is written to an append-only audit log the agency can filter and export.

Transport and headers

HTTPS only in production with HSTS, a strict content security policy that loads nothing from third parties, frame denial and MIME sniffing disabled.

Assurance status

[PLACEHOLDER — replace with the operator's hosting certification, IRAP assessment and penetration test status, with dates before showing Remit to an agency.]

Reporting a vulnerability

[PLACEHOLDER — replace with the operator's security contact and disclosure process before showing Remit to an agency.]