Cybersecurity, Privacy & Access

TRUST IS PART OF THE ARCHITECTURE.

Safety information is sensitive. SAFECITY OS is being designed so that security, privacy and accountability are built in from the start — not added later.

Security Principles

FOUR PRINCIPLES

Design principles
01

Protect

Information is designed to be protected in transit and at rest, using established practices.

02

Control Access

People see only what their role and organisation are authorised to see.

03

Minimise

Collect and share the least information needed for a safety purpose.

04

Account

Important actions are designed to be recorded so they can be reviewed.

Role-Based Access

THE RIGHT ACCESS FOR THE RIGHT ROLE

An illustrative access model. Actual roles and permissions would be agreed per deployment.

Access modelConcept
  • Community memberTheir own reports and public alerts
  • Institutional userInformation relevant to their institution
  • Authorised responderIncidents assigned to their team
  • AdministratorConfiguration and access management
Privacy by Design

PRIVACY IS NOT OPTIONAL

PURPOSE LIMITATION

Information used only for the safety purpose it was shared for.

RETENTION RULES

Information kept only as long as agreed policies allow.

LEGAL ALIGNMENT

Designed to align with applicable privacy law in each deployment, such as POPIA in South Africa.

Honest Status

WHERE THINGS STAND

No certifications, audits or compliance approvals are claimed at this stage.

Current (website)
  • •Public website only — no operational data is held
  • •Demo requests handled server-side; secrets never sent to the browser
In design
  • •Role-based access model
  • •Audit trail of key actions
  • •Privacy-by-design data handling
Before any deployment
  • •Independent security review
  • •Data protection impact assessment
  • •Deployment-specific governance agreements

HAVE SECURITY OR PRIVACY QUESTIONS?

We welcome early conversations with security, privacy and governance teams.