
Privacy & Security by Design
This page states implemented pilot controls and the release gates for an operational Sentinel360 deployment.
Current pilot controls
- Only an Administrator can add an active account; a new account must replace its initial password before access.
- Administrator and Management login require an Authenticator code. Normal User accounts share the same database but use a separate User interface.
- Passwords are stored as salted scrypt hashes. Authenticator secrets are encrypted using a separate local key.
- Normal users can view only incidents submitted from their own account. Audit entries record account creation and incident actions.
- Docker publishes the pilot service on laptop loopback only. Contact OTP is not configured; no verified status is implied.
Required before operational launch
- Approved organization-specific identity verification, granular permissions, restricted-incident access, and independently reviewed audit retention.
- Documented privacy impact assessment, DPO contact, data retention and disposal schedule, incident response, and backup/restore tests.
- HTTPS, managed secrets, security assessment, availability monitoring, and verified responder delivery/acknowledgement.
- Production database migration with reconciliation of all retained pilot records.
On-duty location controls
Location sharing is off by default. Verified responders may enable it while on duty and stop it at any time. The browser also requires location permission. Only dispatchers granted responder-location access can query precise current positions, with audited access. Station coordinates are not treated as officer locations. Proximity is straight-line distance and must be reviewed by the human dispatcher. Deployment must establish its location-sharing policy, access authorization, retention and privacy contacts before operational use.
