Trust

Security without spectacle.

The objective is simple: reduce unnecessary exposure, separate access by role and keep sensitive workflows out of the public layer whenever possible.

Approach

Core security principles

Least privilege

Access should be limited to the minimum permissions needed for a legitimate task, especially for administrative, clinical and professional workflows.

Separation of concerns

Public website content, user accounts, assessment data, professional applications and administrative functions are designed as distinct layers rather than one unrestricted system.

Server-side secrets

Private credentials and service-role keys must remain server-side. Client applications should only receive publishable credentials intended for browser use.

Controlled change

Technical changes should be tested before production deployment, with production kept on a stable source branch and high-risk integrations introduced progressively.

Responsible disclosure

If you discover a security issue

Please report suspected security issues privately to hello@integralvalues.eu. Do not include unnecessary personal, clinical or third-party data in the report.

We ask researchers and users not to exploit vulnerabilities, disrupt services, access data that is not theirs or publish sensitive details before there has been a reasonable opportunity to assess and correct the issue.

Boundaries

Security is continuous

No digital system can be described as risk-free. Integral Values therefore treats security as an ongoing process of minimisation, review, access control and careful deployment rather than as a one-time certification claim.

Book a Consultation