Statement
Security
Last updated 4 September 2026
How Remit protects agency information, and what remains to be certified before production use.
Access
Sign-in with the agency's Microsoft Entra ID account (single sign-on with the agency's own multi-factor policies) or an agency-issued password. No self-registration. Sessions expire and are revoked on sign-out.
Separation between agencies
Every database query is scoped to the signed-in user's agency. Uploaded files are stored outside the web root and served only through authenticated, agency-checked routes.
Audit
Every create, update, approval, export, sign-in and AI call is written to an append-only audit log the agency can filter and export.
Transport and headers
HTTPS only in production with HSTS, a strict content security policy that loads nothing from third parties, frame denial and MIME sniffing disabled.
Assurance status
[PLACEHOLDER — replace with the operator's hosting certification, IRAP assessment and penetration test status, with dates before showing Remit to an agency.]
Reporting a vulnerability
[PLACEHOLDER — replace with the operator's security contact and disclosure process before showing Remit to an agency.]