Least privilege
Access should be limited to the minimum permissions needed for a legitimate task, especially for administrative, clinical and professional workflows.
Trust
The objective is simple: reduce unnecessary exposure, separate access by role and keep sensitive workflows out of the public layer whenever possible.
Approach
Access should be limited to the minimum permissions needed for a legitimate task, especially for administrative, clinical and professional workflows.
Public website content, user accounts, assessment data, professional applications and administrative functions are designed as distinct layers rather than one unrestricted system.
Private credentials and service-role keys must remain server-side. Client applications should only receive publishable credentials intended for browser use.
Technical changes should be tested before production deployment, with production kept on a stable source branch and high-risk integrations introduced progressively.
Responsible disclosure
Please report suspected security issues privately to hello@integralvalues.eu. Do not include unnecessary personal, clinical or third-party data in the report.
We ask researchers and users not to exploit vulnerabilities, disrupt services, access data that is not theirs or publish sensitive details before there has been a reasonable opportunity to assess and correct the issue.
Boundaries
No digital system can be described as risk-free. Integral Values therefore treats security as an ongoing process of minimisation, review, access control and careful deployment rather than as a one-time certification claim.