Security and data
Policies can be changed. Separation that is built into the system cannot be undone by a decision. Here is what the system does not permit, whoever asks.
Phone numbers, customer references and recipient lists are not available to the central panel. Not hidden in the interface — not served by the backend at all. Central operations work from summaries.
An institution can see the outcome of the messages it sent. It cannot see a person’s other institutions, and the person’s phone number is not exposed to it.
Shared while an SOS is active, with the guardians the person selected. Not before it starts, not after it ends.
An append-only audit record of who did what and when — the same record that makes proof of service possible in the first place.
Legal basis
ADORASEC Ltd is registered in England and Wales and operates under the UK GDPR and the Data Protection Act 2018. Data is processed in the United Kingdom and the European Economic Area.
Where an institution uses ADORASEC to reach its own residents or customers, that institution is the controller and we are the processor. The terms say so, and our architecture is built so that we could not act otherwise.
We do not sell data, we do not profile recipients, and we do not read message content for any purpose other than delivering it.
You should not, on our word. That is why the separation is architectural rather than contractual, why the audit record exists, and why we publish our underlying research including the parts that do not flatter us.
We are open to audit, to independent review of the architecture, and to joint working with an institution’s own security and data protection teams. We would rather be checked than trusted.
Honest status
Some of what this site describes is running today. Some is in build. We say which, because an institution that finds out later has every right to stop trusting the rest.
Counter-verified identity · verified sender channel · structured replies with coded answers · delivery, read, reply and failure counts · backend role separation · audit logging · per-person evidence line with exportable certificate.
Consent record export · auditor role · four-eyes authorisation and emergency pause · subject access export.